UNKNOWN OpenStack
CVE-2026-55707
OSSA-2026-032: Subnetpool onboarding cross-project subnet mutation
Tim Shephard from roiai.ca reported a vulnerability in Neutron’s subnetpool onboarding API. A project member can onboard subnets from another project’s shared network into their own subnetpool, mutating the victim’s persistent subnet state and altering L3 routing, NAT, and address-scope behavior for victim routers. Only deployments with shared or RBAC-shared networks and the subnetpool onboarding extension enabled are affected. Patches ¶ https://review.opendev.org/999134 (2025.1/epoxy) https://r
Affected Products
- Neutron: >=14.0.0 <26.0.6, >=27.0.0 <27.0.4, >=28.0.0 <28.0.2
- CVE-2026-55707
References
- https://security.openstack.org/ossa/OSSA-2026-032.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-55707
This unknown severity vulnerability was published on 2026-07-29 via OpenStack. Affected: Neutron: >=14.0.0 <26.0.6, >=27.0.0 <27.0.4, >=28.0.0 <28.0.2, CVE-2026-55707.
vulnfeed aggregates 14649 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.