PT-2026-84143 · Unknown · Qemu-Agent+1
CVE-2026-84165
·
Published
2026-09-01
·
Updated
2026-09-02
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenNebula versions prior to 7.4
Description
Incorrect access control allows an authenticated user with basic permissions to execute commands on virtual machines belonging to other users. This occurs via the
one.vm.exec function due to a lack of proper access permission verification. Exploitation requires the attacker to know the virtual machine identifier and for the qemu-agent (a management agent for QEMU virtual machines) to be enabled on the target machine. This could compromise the confidentiality, integrity, and availability of the affected virtual machines.Recommendations
Update to version 7.4 or later.
As a temporary workaround, restrict the use of the
one.vm.exec function or disable the qemu-agent on virtual machines to minimize the risk of exploitation.Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opennebula
Qemu-Agent