CVE-2026-66139 Details
Description
OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
A vulnerability in OpenStack Zaqar versions through 22.0.0 allows for authentication bypass via the EXTRA-SPEC header, when a UUID is known. This issue arises because the EXTRA-SPEC header was intended to support alternative validation methods but lacks proper backend implementation. As a result, an unauthenticated client can manipulate queue operations without a Keystone token or project role.
Users can upgrade to OpenStack Zaqar versions 20.1.1, 21.0.1, or 22.0.1, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2026CISA-ADP
Assessed Jul 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/24/27 | CVE | |
| https://bugs.launchpad.net/ossa/+bug/2161254 | [email protected] | ExploitIssue TrackingRemedyTechnical DescriptionVendor |
| https://www.openwall.com/lists/oss-security/2026/07/23/7 | [email protected] | Mailing ListRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenStack Zaqar | >= 12.0.0, < 20.1.1 (semver) = 21.0.0 (semver) = 22.0.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 25, 2026 | CVE Modified | CVE |
| Jul 24, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2026 | New CVE Received | [email protected] |
Volerion