CVE-2026-107363
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may substitute another project's UUID to enumerate, inspect, create, or delete queues belonging to that project, resulting in unauthorized disclosure, modification, or loss of queue data. Only deployments using the WebSocket transport with Keystone authentication are affected.
| CWE | CWE-472 |
| Vendor | openstack |
| Product | zaqar |
| Published | Oct 7, 2026 |
| Last Updated | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for openstack zaqar
Be the first to know when new unknown vulnerabilities affecting openstack zaqar are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
OpenStack / Zaqar
1.0.0 < 20.1.3 21.0.0 < 21.0.3 22.0.0 < 22.0.3 23.0.0 < 23.0.1