CVE-2026-49299
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.
| CWE | CWE-863 |
| Vendor | openstack |
| Product | neutron |
| Published | May 28, 2026 |
| Last Updated | Jun 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for openstack neutron
Be the first to know when new unknown vulnerabilities affecting openstack neutron are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
OpenStack / Neutron
26.0.0 < 26.0.4 27.0.0 < 27.0.3 28.0.0 < 28.0.1