CVE-2026-40213 Details
Description
OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC.
A vulnerability in OpenStack Cyborg versions prior to 16.0.1 allows authenticated users to bypass access controls on several API endpoints. The default policy 'rule:allow' unconditionally authorizes requests with a valid Keystone token, regardless of roles or project membership. This vulnerability enables users with no role assignments to access sensitive information and perform privileged actions, such as reprogramming FPGA bitstreams on compute nodes and manipulating hardware metadata used by the Placement service.
Users can update to OpenStack Cyborg versions 16.0.1 or later, where this vulnerability has been fixed. Instructions for applying the update can be found in the OpenStack Cyborg release notes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | CVE Modified | [email protected] |
| May 7, 2026 | New CVE Received | [email protected] |