SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66139

MEDIUM · CVSS 4.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

OpenStack Zaqar versions up to 22.0.0 are vulnerable to an authentication bypass due to improper handling of the EXTRA-SPEC header when a UUID is known, potentially allowing unauthorized access to the messaging service. This vulnerability poses a medium risk as it could lead to unauthorized actions within the affected environment. Organizations utilizing OpenStack Zaqar should prioritize remediation to mitigate potential security breaches.

CVE
CVE-2026-66139
Severity
MEDIUM
CVSS
4.8
EPSS
0.29%

Original NVD Description

OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.