Access Control Vulnerability in OpenNebula by OpenNebula Systems
CVE-2026-84165
8.7HIGH
What is CVE-2026-84165?
An access control vulnerability in OpenNebula allows authenticated users with basic permissions to execute commands on virtual machines owned by other users through the one.vm.exec function. This issue arises from inadequate verification of access permissions, permitting exploitation if the attacker knows the virtual machine's identifier and if qemu-agent is enabled. Successfully exploiting this flaw could lead to severe impacts on the confidentiality, integrity, and availability of the affected virtual machines.
Affected Version(s)
OpenNebula 0 < 7.4
