Quality of Service Policy Authorization Flaw in OpenStack Octavia
CVE-2026-74248

4.3MEDIUM

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-74248?

OpenStack Octavia versions up to 18.0.0 exhibit a vulnerability in the handling of quality of service (QoS) policy authorization. This flaw allows an authenticated user to associate another project's QoS policy with an amphora, which can effectively prevent the deletion of that policy. Since all deployments of Octavia are susceptible, it is crucial for organizations using this platform to assess their configurations and apply appropriate security measures to mitigate the risk associated with this vulnerability.

Affected Version(s)

Octavia 0 < 16.0.2

Octavia 17.0.0

Octavia 18.0.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.