SEPTEMBER 23, 2026
Live Feed
Back to database
Case File

CVE-2026-40214

MEDIUM · CVSS 6.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-05-07 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.3. It may lead to a denial-of-service condition.

CVE
CVE-2026-40214
Severity
MEDIUM
CVSS
6.3
EPSS
0.21%

Original NVD Description

In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares the caller's project_id with itself rather than the target resource). Any authenticated non-admin user can complete various actions such as deleting ARQs bound to other projects' instances, aka cross-tenant denial of service.