What is CVE-2026-55707?
In OpenStack Neutron before version 28.0.2, a vulnerability (CVE-2026-55707) exists where the subnetpool onboarding API fails to verify ownership of target subnets. This allows an authenticated user to onboard subnets from another project's shared network into their own subnetpool, potentially mutating the victim's subnet state and altering L3 routing and address scope configurations.
Azərbaycanca: OpenStack Neutron-da aşkar edilən CVE-2026-55707 zəifliyi, subnetpool onboarding API-nin hədəf subnetlər üzərində mülkiyyət yoxlaması aparmaması səbəbindən autentifikasiya olunmuş istifadəçiyə başqa layihənin paylaşılan şəbəkəsindəki subnetləri öz subnetpooluna əlavə etməyə imkan verir. Bu, qurbanın subnet vəziyyətinin dəyişdirilməsinə, həmçinin L3 routing və address scope parametrlərinin manipulyasiyasına yol aça bilər. Təsirə məruz qalan sistemlərin 28.0.2 versiyasına qədər yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of OpenStack Neutron are affected by CVE-2026-55707?
The vulnerability affects OpenStack Neutron versions before 28.0.2.
What can an authenticated user do by exploiting CVE-2026-55707?
An authenticated user can onboard subnets from another project's shared network into their own subnetpool, potentially mutating the victim's subnet state and altering L3 routing and address scope configurations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.