CVE-2026-50266Low· 2.2▾ SunlitOpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
▾ Sunlit zone — Low / medium · no exploitation signal
impact 12.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 16.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.3%
Last analysed / modified upstream
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has "network:" at the beginning ("network:dhcp" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018).
neutron < 28.0.1Upgrade to a patched release:
neutron 28.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-49299MediumOpenStack Neutron has an Incorrect Authorization issue
CVE-2022-3277Medium· 6.5openstack-neutron uncontrolled resource consumption flaw
CVE-2016-5362High· 8.2OpenStack Neutron allows remote attackers to bypass an intended DHCP-spoofing protection mechanism
CVE-2015-5240LowOpenStack Neutron Race condition vulnerability
CVE-2024-53916High· 7.5OpenStack Neutron can use an incorrect ID during policy enforcement
CVE-2016-5363High· 8.2OpenStack Neutron Intended MAC-spoofing protection mechanism bypass