๐Ÿ” CVE Alert

CVE-2026-71192

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed PUT request targeting their own bucket, causing Swift to perform a server-side copy from another tenant's private object. The source object authorization is bypassed because the S3API middleware has already authorized the request against the destination. The attacker can read any object whose project_id, container name, and object name are known, regardless of the source object's ACLs or ownership. This requires the non-default s3_acl=true configuration.

CWE CWE-863
Vendor openstack
Product swift
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for openstack swift

Be the first to know when new unknown vulnerabilities affecting openstack swift are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenStack / Swift
2.18.0 < 2.35.4 2.36.0 < 2.36.3 2.37.0 < 2.37.3 2.38.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
launchpad.net: https://launchpad.net/bugs/2158733 openwall.com: https://openwall.com/lists/oss-security/2026/07/28/26 security.openstack.org: https://security.openstack.org/ossa/OSSA-2026-030.html