๐Ÿ” CVE Alert

CVE-2026-107363

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may substitute another project's UUID to enumerate, inspect, create, or delete queues belonging to that project, resulting in unauthorized disclosure, modification, or loss of queue data. Only deployments using the WebSocket transport with Keystone authentication are affected.

CWE CWE-472
Vendor openstack
Product zaqar
Published Oct 7, 2026
Last Updated Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for openstack zaqar

Be the first to know when new unknown vulnerabilities affecting openstack zaqar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenStack / Zaqar
1.0.0 < 20.1.3 21.0.0 < 21.0.3 22.0.0 < 22.0.3 23.0.0 < 23.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
launchpad.net: https://launchpad.net/bugs/2161402 openwall.com: https://www.openwall.com/lists/oss-security/2026/10/07/30