WebSocket Transport Vulnerability in OpenStack Zaqar Affects Project Data Security
CVE-2026-107363
6.1MEDIUM
What is CVE-2026-107363?
A vulnerability exists in OpenStack Zaqar versions before 23.0.1, where the WebSocket transport fails to correctly bind the project identifier in requests after the initial connection. This allows an authenticated user with a valid Keystone token for one project to impersonate another project, potentially enabling them to enumerate, inspect, create, or delete queues that belong to another project. This exploitation leads to unauthorized disclosure, modification, or loss of crucial queue data, particularly in environments utilizing WebSocket transport with Keystone authentication.
Affected Version(s)
Zaqar 1.0.0 < 20.1.3
Zaqar 21.0.0 < 21.0.3
Zaqar 22.0.0 < 22.0.3
