🔐 CVE Alert

CVE-2026-84165

UNKNOWN 0.0

Lack of authorisation in OpenNebula by OpenNebula Systems

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines.

CWE CWE-284
Vendor opennebula systems
Product opennebula
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for opennebula systems opennebula

Be the first to know when new unknown vulnerabilities affecting opennebula systems opennebula are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

OpenNebula Systems / OpenNebula
0 < 7.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/lack-authorisation-opennebula-opennebula-systems

Credits

Yonghwa Lee, Xint from Theori.