CVE-2026-49299 Details
Description
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.
A vulnerability exists in OpenStack Neutron's tagging controller in versions 26.0.0 prior to 26.0.4, 27.0.0 prior to 27.0.3, and 28.0.0 prior to 28.0.1. The issue arises because the controller applies plural policy action names to single-tag write operations, while the corresponding policy rules are defined in singular terms. This discrepancy allows project readers to create and modify tags on same-project resources, bypassing intended policy restrictions.
Users can upgrade to Neutron versions 26.0.4, 27.0.3, or 28.0.1, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 28, 2026CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/02/7 | CVE | |
| https://bugs.launchpad.net/bugs/2150132 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://review.opendev.org/c/openstack/neutron/+/989099 | [email protected] | Source CodeVendor |
| https://www.openwall.com/lists/oss-security/2026/05/28/8 | [email protected] | AdvisoryMailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenStack Neutron | >= 26.0.0, < 26.0.4 (semver) >= 27.0.0, < 27.0.3 (semver) >= 28.0.0, < 28.0.1 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | CVE Modified | CVE |
| May 28, 2026 | New CVE Received | [email protected] |
Volerion