Project Scope Bypass in OpenStack Aodh API
CVE-2026-76878

8.4HIGH

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76878?

In OpenStack Aodh versions before 22.0.1, a critical vulnerability exists where the alarm list API can be accessed without proper project scoping. Specifically, when the 'all_projects' query parameter is set to false, the API incorrectly checks for the presence of the key instead of its value. This misconfiguration allows non-admin users with reader roles to list alarms across all projects. As a result, sensitive information such as alarm actions, trust webhook URLs, Heat signal endpoints, project IDs, and user IDs can be exposed. Additionally, the OpenStack Watcher component fails to enforce authorization on its webhook trigger endpoints, potentially allowing any authenticated user who discovers an audit's webhook URL to initiate audits and their associated action plans, irrespective of their project or role. This issue highlights the need for stricter security measures in API access and authorization to prevent unauthorized exploitation.

Affected Version(s)

Aodh 10.0.0 < 20.0.1

Aodh 21.0.0 < 21.0.1

Aodh 22.0.0 < 22.0.1

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.