OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.

Project Subscriptions

Vendors Products
Openstack Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 03 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in OpenStack Zaqar via EXTRA‑SPEC Header

Thu, 30 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass in OpenStack Zaqar via EXTRA‑SPEC Header

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Openstack
Openstack zaqar
Vendors & Products Openstack
Openstack zaqar

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Description OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-24T23:22:06.300Z

Reserved: 2026-07-24T04:14:41.411Z

Link: CVE-2026-66139

cve-icon Vulnrichment

Updated: 2026-07-24T23:22:06.300Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:45:03Z

Weaknesses