---
id: CVE-2016-0757
aliases:
  - GHSA-5xrj-ghhp-hx7p
  - PYSEC-2026-811
title: OpenStack Image Service (Glance) vulnerable to Improper Access Control
summary: OpenStack Image Service (Glance) vulnerable to Improper Access Control
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
vendor: glance
product: glance
ecosystem: pip
affected:
  - 'glance >= 11.0.0, < 11.0.2'
patched:
  - glance 11.0.2
published: '2022-05-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-5xrj-ghhp-hx7p'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2016-0757'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0309'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0352'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0354'
  - url: 'https://access.redhat.com/errata/RHSA-2016:0358'
  - url: 'https://access.redhat.com/security/cve/CVE-2016-0757'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1302607'
  - url: 'https://opendev.org/openstack/glance'
  - url: 'https://rhn.redhat.com/errata/RHSA-2016-0309.html'
  - url: 'https://security.openstack.org/ossa/OSSA-2016-006.html'
  - url: >-
      https://web.archive.org/web/20210123081823/https://www.securityfocus.com/bid/82696
tags:
  - osv
  - pip
epss: 0.01741
epssPercentile: 0.76422
ingestedAt: '2026-07-08T18:25:46.250Z'
---

## Overview

OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.

## Affected packages

- `glance >= 11.0.0, < 11.0.2`

## Remediation

Upgrade to a patched release:

- `glance 11.0.2`
