UNKNOWN OpenStack
CVE-2026-50266
OSSA-2026-021: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
Tim Shephard from roiai.ca reported a policy enforcement bypass in Neutron’s default port RBAC rules. A project manager can create or update a port on a shared network owned by another project and set device_owner to a trusted network-service value such as network:dhcp . Depending on backend and deployment, this can bypass anti-spoofing and security group protections. This is a regression of CVE-2015-5240 (OSSA-2015-018) introduced by the manager role support change. Deployments running Neutron
Affected Products
- Neutron: >=25.0.0 <25.2.4, >=26.0.0 <26.0.4, >=27.0.0 <27.0.3, ==28.0.0
- CVE-2026-50266
- CVE-2015-5240
References
- https://security.openstack.org/ossa/OSSA-2026-021.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-50266
- https://nvd.nist.gov/vuln/detail/CVE-2015-5240
This unknown severity vulnerability was published on 2026-06-04 via OpenStack. Affected: Neutron: >=25.0.0 <25.2.4, >=26.0.0 <26.0.4, >=27.0.0 <27.0.3, ==28.0.0, CVE-2026-50266, CVE-2015-5240.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.