---
id: CVE-2026-74248
title: >-
  OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy
  authorization
summary: >-
  OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy
  authorization. By associating another project's QoS policy with an amphora, an
  authenticated user may prevent deletion of that policy. All Octavia
  deployments ar…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-863
published: '2026-08-14'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:03:22.897'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-74248'
references:
  - url: 'https://bugs.launchpad.net/octavia/+bug/2161500'
    label: cve@mitre.org
  - url: 'https://www.openwall.com/lists/oss-security/2026/08/13/12'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/08/17/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugs.launchpad.net/octavia/+bug/2161500'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00208
epssPercentile: 0.11269
ingestedAt: '2026-09-09T16:14:05.513Z'
---

## Overview

OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
