Shell Metacharacter Vulnerability in OpenStack Horizon by OpenStack
CVE-2026-55748

6MEDIUM

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
17 June 2026

What is CVE-2026-55748?

OpenStack Horizon prior to version 25.7.4 contains a vulnerability that allows for crafted project names containing shell metacharacters. This could potentially lead to unintended command execution, highlighting a need for careful validation of user inputs. Some experts argue that this issue can be viewed as a security hardening measure against advanced user errors, rather than a typical security vulnerability.

Affected Version(s)

Horizon 8.0.0 < 25.3.3

Horizon 25.4.0 < 25.5.3

Horizon 25.6.0 < 25.7.4

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.