๐Ÿ” CVE Alert

CVE-2026-49299

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.

CWE CWE-863
Vendor openstack
Product neutron
Published May 28, 2026
Last Updated Jun 2, 2026
Stay Ahead of the Next One

Get instant alerts for openstack neutron

Be the first to know when new unknown vulnerabilities affecting openstack neutron are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenStack / Neutron
26.0.0 < 26.0.4 27.0.0 < 27.0.3 28.0.0 < 28.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
bugs.launchpad.net: https://bugs.launchpad.net/bugs/2150132 review.opendev.org: https://review.opendev.org/c/openstack/neutron/+/989099 openwall.com: https://www.openwall.com/lists/oss-security/2026/05/28/8 openwall.com: http://www.openwall.com/lists/oss-security/2026/06/02/7