PT-2026-84143 · Unknown · Qemu-Agent+1

CVE-2026-84165

·

Published

2026-09-01

·

Updated

2026-09-02

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenNebula versions prior to 7.4
Description Incorrect access control allows an authenticated user with basic permissions to execute commands on virtual machines belonging to other users. This occurs via the one.vm.exec function due to a lack of proper access permission verification. Exploitation requires the attacker to know the virtual machine identifier and for the qemu-agent (a management agent for QEMU virtual machines) to be enabled on the target machine. This could compromise the confidentiality, integrity, and availability of the affected virtual machines.
Recommendations Update to version 7.4 or later. As a temporary workaround, restrict the use of the one.vm.exec function or disable the qemu-agent on virtual machines to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84165

Affected Products

Opennebula
Qemu-Agent