CVE-2026-49299Medium▾ SunlitOpenStack Neutron has an Incorrect Authorization issue
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.
neutron >= 28.0.0, < 28.0.1neutron >= 27.0.0, < 27.0.3neutron >= 26.0.0, < 26.0.4Upgrade to a patched release:
neutron 28.0.1neutron 27.0.3neutron 26.0.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-50266Low· 2.2OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
CVE-2022-3277Medium· 6.5openstack-neutron uncontrolled resource consumption flaw
CVE-2016-5362High· 8.2OpenStack Neutron allows remote attackers to bypass an intended DHCP-spoofing protection mechanism
CVE-2015-5240LowOpenStack Neutron Race condition vulnerability
CVE-2024-53916High· 7.5OpenStack Neutron can use an incorrect ID during policy enforcement
CVE-2016-5363High· 8.2OpenStack Neutron Intended MAC-spoofing protection mechanism bypass