UNKNOWN OpenStack
CVE-2026-49299
OSSA-2026-016: Neutron tagging policy bypass allows project readers to mutate tags
Tim Shephard from roiai.ca reported a policy enforcement bypass in Neutron’s tagging controller. The controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.
Affected Products
- Neutron: >=26.0.0 <26.0.4, >=27.0.0 <27.0.3, >=28.0.0 <28.0.1
- CVE-2026-49299
References
- https://security.openstack.org/ossa/OSSA-2026-016.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-49299
This unknown severity vulnerability was published on 2026-05-28 via OpenStack. Affected: Neutron: >=26.0.0 <26.0.4, >=27.0.0 <27.0.3, >=28.0.0 <28.0.1, CVE-2026-49299.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.