UNKNOWN OpenStack
CVE-2026-76878
OSSA-2026-036: Aodh cross-project alarm enumeration and Watcher webhook authorization bypass
Chen YuXiang of the Institute of Computing Technology, Chinese Academy of Sciences reported that OpenStack Aodh does not enforce project scope on the alarm listing API when the all_projects query parameter is supplied with a false value. A non-admin user holding only the reader role can list alarms belonging to other projects, optionally targeting a specific project, exposing alarm metadata such as webhook action URLs, signal endpoints, and project identifiers. All Aodh deployments are affected.
Affected Products
- Aodh: >=10.0.0 <20.0.1, ==21.0.0, ==22.0.0 Watcher: >=4.0.0 <14.1.2, >=15.0.0 <15.1.2, >=16.0.0 <16.0.2
- CVE-2026-76878
References
- https://security.openstack.org/ossa/OSSA-2026-036.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-76878
This unknown severity vulnerability was published on 2026-08-19 via OpenStack. Affected: Aodh: >=10.0.0 <20.0.1, ==21.0.0, ==22.0.0 Watcher: >=4.0.0 <14.1.2, >=15.0.0 <15.1.2, >=16.0.0 <16.0.2, CVE-2026-76878.
vulnfeed aggregates 10551 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.