CVE-2026-55707 Details
Description
In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers.
A vulnerability exists in OpenStack Neutron versions 14.0.0 prior to 26.0.6, 27.0.0 prior to 27.0.4, and 28.0.0 prior to 28.0.2. The issue arises in the subnetpool onboarding API, where ownership of target subnets is not properly verified. This allows an authenticated user to onboard subnets from another project's shared network into their own subnetpool. As a result, the victim's subnet state is altered, impacting L3 routing, NAT, and address-scope behavior for the affected routers. The vulnerability is present in deployments with shared or RBAC-shared networks, and with the subnetpool onboarding extension enabled.
Users can upgrade to OpenStack Neutron versions 26.0.6, 27.0.4, or 28.0.2 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 5, 2026CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2026/08/msg00024.html | CVE | |
| http://www.openwall.com/lists/oss-security/2026/07/29/5 | CVE | AdvisoryMailing ListRemedy |
| https://launchpad.net/bugs/2152113 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://security.openstack.org/ossa/OSSA-2026-032.html | [email protected] | AdvisoryRemedyVendor |
| https://www.openwall.com/lists/oss-security/2026/07/29/5 | [email protected] | AdvisoryMailing ListRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenStack Neutron | >= 14.0.0, < 26.0.6 (semver) >= 27.0.0, < 27.0.4 (semver) >= 28.0.0, < 28.0.2 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 12, 2026 | CVE Modified | CVE |
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |
| Aug 5, 2026 | CVE Modified | CVE |
Volerion