Quality of Service Policy Authorization Flaw in OpenStack Octavia
CVE-2026-74248
4.3MEDIUM
What is CVE-2026-74248?
OpenStack Octavia versions up to 18.0.0 exhibit a vulnerability in the handling of quality of service (QoS) policy authorization. This flaw allows an authenticated user to associate another project's QoS policy with an amphora, which can effectively prevent the deletion of that policy. Since all deployments of Octavia are susceptible, it is crucial for organizations using this platform to assess their configurations and apply appropriate security measures to mitigate the risk associated with this vulnerability.
Affected Version(s)
Octavia 0 < 16.0.2
Octavia 17.0.0
Octavia 18.0.0
