What is CVE-2026-66139?
CVE-2026-66139 is an authentication bypass vulnerability in OpenStack Zaqar up to version 22.0.0. An attacker can bypass authentication using the `EXTRA-SPEC` header when a UUID is known. Affected systems should be immediately patched and network access restricted.
Azərbaycanca: CVE-2026-66139 OpenStack Zaqar-ın 22.0.0 daxil olmaqla bütün versiyalarını təsir edən autentifikasiyadan yan keçmə zəifliyidir. Hücumçu, məlum UUID olduqda `EXTRA-SPEC` header-i vasitəsilə autentifikasiyanı keçə bilər. Sistem inzibatçıları dərhal təhlükəsizlik yaması tətbiq etməli və şəbəkə girişini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which software product is affected by CVE-2026-66139?
CVE-2026-66139 is an authentication bypass vulnerability affecting all versions of OpenStack Zaqar up to 22.0.0.
How can an attacker exploit the CVE-2026-66139 vulnerability?
An attacker can bypass authentication using the `EXTRA-SPEC` header when a UUID is known.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.