OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-97404

CRITICAL · CVSS 9.2 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

OpenStack Zaqar versions prior to 22.0.2 are vulnerable due to a flaw in the WSGI transport that allows unauthenticated remote attackers to bypass Keystone authentication by exploiting an empty URL-Signature header. This vulnerability enables attackers to manipulate project resources, including reading, creating, and deleting queues and messages, and potentially gain administrative access to manage pools and flavors. Organizations utilizing OpenStack Zaqar with WSGI transport and authentication strategies should prioritize patching to mitigate this critical risk.

CVE
CVE-2026-97404
Severity
CRITICAL
CVSS
9.2
EPSS
0.27%

Original NVD Description

In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target project's UUID may bypass both Keystone authentication and pre-signed URL verification, resulting in the ability to read, enumerate, create, and delete that project's queues, messages, claims, and subscriptions. By additionally claiming an administrative role, the attacker may also perform administrative operations, such as managing pools and flavors in admin_mode deployments. Only deployments using the WSGI transport with an authentication strategy configured are affected; the websocket transport is not affected.