What is CVE-2026-74248?
OpenStack Octavia up to version 18.0.0 mishandles QoS policy authorization. An authenticated user can associate another project's QoS policy with an amphora, preventing its deletion. All Octavia deployments are affected; updating to the latest patched version is recommended.
Azərbaycanca: OpenStack Octavia 18.0.0-a qədər versiyalarda QoS siyasətinin icazə mexanizmində zəiflik aşkarlanıb. Doğrulanmış istifadəçi başqa layihənin QoS siyasətini öz amphora-sı ilə əlaqələndirərək həmin siyasətin silinməsinə mane ola bilər. Octavia yerləşdirmələrini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of OpenStack Octavia are affected by CVE-2026-74248?
OpenStack Octavia versions up to 18.0.0 are affected by this vulnerability.
What can an authenticated user do by exploiting CVE-2026-74248?
An authenticated user can associate another project's QoS policy with an amphora, preventing its deletion.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.