UNKNOWN OpenStack

CVE-2026-76878

OSSA-2026-036: Aodh cross-project alarm enumeration and Watcher webhook authorization bypass

Chen YuXiang of the Institute of Computing Technology, Chinese Academy of Sciences reported that OpenStack Aodh does not enforce project scope on the alarm listing API when the all_projects query parameter is supplied with a false value. A non-admin user holding only the reader role can list alarms belonging to other projects, optionally targeting a specific project, exposing alarm metadata such as webhook action URLs, signal endpoints, and project identifiers. All Aodh deployments are affected.

Affected Products

References

Published: 2026-08-19 · Source: OpenStack · Feed updated: 2026-10-04
This unknown severity vulnerability was published on 2026-08-19 via OpenStack. Affected: Aodh: >=10.0.0 <20.0.1, ==21.0.0, ==22.0.0 Watcher: >=4.0.0 <14.1.2, >=15.0.0 <15.1.2, >=16.0.0 <16.0.2, CVE-2026-76878.
vulnfeed aggregates 10551 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.