๐Ÿ” CVE Alert

CVE-2026-55707

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers.

CWE CWE-863
Vendor openstack
Product neutron
Published Aug 5, 2026
Last Updated Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for openstack neutron

Be the first to know when new unknown vulnerabilities affecting openstack neutron are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenStack / Neutron
14.0.0 < 26.0.6 27.0.0 < 27.0.4 28.0.0 < 28.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
launchpad.net: https://launchpad.net/bugs/2152113 security.openstack.org: https://security.openstack.org/ossa/OSSA-2026-032.html openwall.com: https://www.openwall.com/lists/oss-security/2026/07/29/5 openwall.com: http://www.openwall.com/lists/oss-security/2026/07/29/5