Improper access control in openstack-neutron - CVE-2026-50266

 

Improper access control in openstack-neutron - CVE-2026-50266

Published: June 18, 2026


Vulnerability identifier: #VU134852
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-50266
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass anti-spoofing and security group protections.

The vulnerability exists due to improper access control in Neutron default port RBAC rules when creating or updating a port on a shared network owned by another project. A remote user can set the device_owner field to a trusted network-service value such as network:dhcp to bypass anti-spoofing and security group protections.

Exploitation requires project manager permissions and affects shared networks owned by another project. Depending on backend and deployment, the impact may vary.


Affected software

openstack-neutron
Debian Linux
neutron (Debian package)

How to mitigate CVE-2026-50266

Install security update from vendor's website.

openstack-neutron - addressed in versions 25.2.4, 26.0.4, 27.0.3, 28.0.0
neutron (Debian package) - update to 2:26.0.3-0+deb13u2

External References

Related Security Bulletins