OpenStack Neutron Vulnerability in Subnetpool API by OpenStack
CVE-2026-55707

7.1HIGH

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-55707?

The OpenStack Neutron software exhibits a vulnerability in its subnetpool onboarding API, which fails to properly verify the ownership of target subnets. This shortcoming allows an authenticated user to onboard subnets from a different project's shared network into their own subnetpool. Consequently, this can lead to unauthorized alterations in the victim's subnet state, affecting L3 routing and address scope behavior for connected routers, resulting in a potential disruption in services and compromised network integrity.

Affected Version(s)

Neutron 14.0.0 < 26.0.6

Neutron 27.0.0 < 27.0.4

Neutron 28.0.0 < 28.0.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.