VDB

CVE-2026-40213

CVE-2026-40213 PUBLISHED CVSS 7.400000095367432 HIGH

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC.

EPSS 0.21% · 11.1th percentile

Risk Scores

CVSS 3.1
7.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
EPSS Score
0.21%
11.1th percentile

Affected Products

VendorProductVersions
OpenStackCyborg5.0.0, 15.0.0, 16.0.0

Timeline

  • May 7, 2026 CVE Published
  • May 7, 2026 PoC Published
  • May 8, 2026 CVE Updated
  • May 8, 2026 Security Advisory
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›