---
id: CVE-2022-23451
aliases:
  - GHSA-p2jg-q8hw-p7gc
  - PYSEC-2026-786
title: Barbican authorization flaw before v14.0.0
summary: Barbican authorization flaw before v14.0.0
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
vendor: barbican
product: barbican
ecosystem: pip
affected:
  - barbican < 14.0.0
patched:
  - barbican 14.0.0
published: '2022-09-07'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-p2jg-q8hw-p7gc'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-23451'
  - url: >-
      https://github.com/openstack/barbican/commit/7d270bacbe29a90a10f1855abc3b50dac0f08022
  - url: 'https://access.redhat.com/errata/RHSA-2022:5114'
  - url: 'https://access.redhat.com/errata/RHSA-2022:8874'
  - url: 'https://access.redhat.com/security/cve/CVE-2022-23451'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2022878'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2025089'
  - url: 'https://github.com/openstack/barbican'
  - url: 'https://review.opendev.org/c/openstack/barbican/+/811236'
tags:
  - osv
  - pip
epss: 0.01253
epssPercentile: 0.68179
ingestedAt: '2026-07-08T18:25:51.488Z'
---

## Overview

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.

## Affected packages

- `barbican < 14.0.0`

## Remediation

Upgrade to a patched release:

- `barbican 14.0.0`
