PT-2026-72119 · Openstack · Openstack Octavia

CVE-2026-74248

·

Published

2026-08-14

·

Updated

2026-08-17

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Octavia versions prior to 18.0.0
Description OpenStack Octavia mishandles quality of service (QoS) policy authorization. An authenticated user can associate a QoS policy belonging to another project with an amphora, which prevents the deletion of that policy.
Recommendations Update OpenStack Octavia to a version later than 18.0.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74248

Affected Products

Openstack Octavia