PT-2026-67962 · Openstack · Openstack Swift
CVE-2026-71191
·
Published
2026-08-05
·
Updated
2026-08-06
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Swift versions prior to 2.38.1
Description
S3API middleware fails to ensure that semantic
x-amz-* headers are included in the SigV4 signature for presigned URL requests. An attacker with a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, forcing the system to perform a server-side copy from an arbitrary source object using the authorization context of the signer. This allows the attacker to read any object accessible to the signer, provided the project id, container name, and object name are known. This issue impacts deployments using the default s3 acl=false configuration.Recommendations
Update OpenStack Swift to version 2.38.1 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Swift