OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-51773

HIGH · CVSS 8.1 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The VMware datastore driver in OpenStack glance_store is vulnerable to an authentication header leakage due to improper validation of image location URIs. An authenticated attacker can exploit this flaw by supplying a crafted URI that points to an external server, potentially exposing sensitive authentication information. Organizations using VMware with OpenStack should prioritize patching this vulnerability to mitigate the risk of unauthorized access and data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51773
Severity
HIGH
CVSS
8.1
EPSS
0.32%
VMware VMWare

Original NVD Description

An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.