PT-2026-97852 · Openstack · Openstack Zaqar

CVE-2026-97404

·

Published

2026-09-24

·

Updated

2026-09-26

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OpenStack Zaqar versions prior to 22.0.2
Description WSGI transport mishandles the URL-Signature header. An unauthenticated remote attacker who knows a target project's UUID can bypass Keystone authentication and pre-signed URL verification by sending a request with an empty URL-Signature header. This allows the attacker to read, enumerate, create, and delete the project's queues, messages, claims, and subscriptions. In deployments using admin mode, claiming an administrative role further enables administrative operations, such as managing pools and flavors. This issue only affects deployments using WSGI transport with a configured authentication strategy; websocket transport is not affected.
Recommendations Update to version 22.0.2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97404

Affected Products

Openstack Zaqar