CVE-2026-28370Disclosure(openstack / vitrage)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openstack vitrage systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of the Vitrage service. All deployments exposing the Vitrage API are affected. This occurs in _create_query_function in vitrage/graph/query.py.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-95

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vitrage

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 11 signals
  • Disclosure: 8 classified signals
  • Peaked 3d ago at 6 mentions (2026-02-27); latest day: 1
  • 11 total mentions across 4 days

Affected systems

Vendors
Products
vitrage

Deep dive

Activity timeline11 mentions / 4d
02356Mentions · 2026-02-27: 6Mentions · 2026-02-28: 2Mentions · 2026-03-04: 2Mentions · 2026-03-08: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-02-28: 2Patch / Workaround · 2026-03-04: 1Technical Details · 2026-02-27: 6Technical Details · 2026-02-28: 2Technical Details · 2026-03-04: 2Technical Details · 2026-03-08: 102-2702-2803-0403-08
Signal classification2 categories
Disclosure
872.7%
Patch
327.3%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-02-276
Disclosure5Patch1
2026-02-282
Disclosure1Patch1
2026-03-042
Disclosure1Patch1
2026-03-081
Disclosure1
Full discourse11 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-28370,OSSA-2026-003: OpenStack Vitrage: Remote code execution through Vitrage query parser https://www.openwall.com/lists/oss-security/2026/03/03/6 A user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under

    Post summary

    A new CVE (CVE‑2026‑28370) is disclosed, revealing RCE via the Vitrage API query parser; no PoC, exploit, patch, or active exploitation details are provided.

    00051510
    4.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Nokia discovers a critical 9.1 RCE flaw (CVE-2026-28370) in OpenStack Vitrage's RCA service. Patch immediately to prevent total host server takeovers. #OpenStack #CyberSecurity #CVE #RCE #CloudSecurity #InfoSec #Vulnerability #PatchAlert #OpenSource https://securityonline.info/critical-rce-vulnerability-discovered-in-openstack-vitrage-root-cause-analysis-service/

    Post summary

    Nokia reports a critical RCE vulnerability (CVE-2026-28370) in OpenStack Vitrage's RCA service, urging immediate patching to prevent host takeover.

    00021238
    10.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A code execution vulnerability (DEBIAN-CVE-2026-28370) has been identified in the query parser of `OpenStack Vitrage` for users with API access. Assess exposure and monitor for official patches. #OpenStack #Vitrage #infosec https://www.pulsepatch.io/posts/cve-2026-28370-openstack-vitrage-code-execution

    Post summary

    A code execution vulnerability in OpenStack Vitrage’s query parser affecting API users has been disclosed; users should assess exposure and await official patches.

    1001066
    1 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28370 (CVSS:9.1, CRITICAL) is Analyzed. In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage..https://nvd.nist.gov/vuln/detail/CVE-2026-28370 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post highlights a critical CVE (CVE-2026-28370) in OpenStack Vitrage's query parser affecting versions before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, with a CVSS score of 9.1, but provides no PoC, exploit, or patch details.

    0000029
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    An unauthorized access flaw in `OpenStack Vitrage` (CVE-2026-28370) allows for eval injection. Administrators should update to v15.0.1. #OpenStack #Vitrage #infosec https://www.pulsepatch.io/posts/cve-2026-28370-openstack-vitrage-eval-injection

    Post summary

    The post announces CVE‑2026‑28370, an eval injection flaw in OpenStack Vitrage, and advises updating to v15.0.1.

    0000046
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28370 In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage… https://www.cve.org/CVERecord?id=CVE-2026-28370

    Post summary

    OpenStack Vitrage’s query parser before versions 12.0.1, 13.0.0, 14.0.0, and 15.0.0 allows a user with API access to trigger code execution, indicating a remote code execution vulnerability.

    00000109
    56.6K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL RCE in OpenStack Vitrage! Authenticated users can execute code on the host (CVE-2026-28370, CVSS 9.1). Patch ASAP or restrict API access. Affects 0, 13.0.0, 14.0.0, 15.0.0. Details: https://radar.offseq.com/threat/cve-2026-28370-cwe-95-improper-neutralization-of-d-e... https://t.co/Uk840TYmnn

    Post summary

    Critical RCE vulnerability CVE‑2026‑28370 in OpenStack Vitrage affecting multiple versions; patch or restrict API access immediately.

    0000069
    270 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28370 Remote Code Execution in OpenStack Vitrage Query Parser Before 15.0.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28370 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text announces CVE-2026-28370 as a remote code execution flaw in OpenStack Vitrage Query Parser versions prior to 15.0.0, linking to vulnerability details and a notification.

    0000048
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28370: CRITICAL] Vulnerability in OpenStack Vitrage allows unauthorized access through query parser, enabling code execution on the service host, compromising system security.#cve,CVE-2026-28370,#cybersecurity https://cvefind.com/CVE-2026-28370

    Post summary

    The post announces a critical OpenStack Vitrage vulnerability that allows code execution via a query parser, but provides no PoC, exploit code, or patch information.

    0000065
    585 followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-28370 pertains to a critical security flaw in OpenStack Vitrage, specifically in its query parser component. The vulnerability arises from improper handling of user-supplied input within the `_create_query_function` method located in `vitrage/graph/query.py`. An attacker with access to the Vitrage API can exploit this flaw to trigger arbitrary code execution on the Vitrage service host, effectively executing malicious code under the privileges of the Vitrage service account. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-28370

    Post summary

    CVE-2026-28370 is a critical RCE flaw in OpenStack Vitrage’s query parser caused by improper user input handling, allowing attackers with API access to execute code on the host. No PoC, exploit, patch, or active exploitation details are provided.

    0000047
    20 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28370 - Critical In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the ... https://www.thehackerwire.com/vulnerability/CVE-2026-28370/ https://t.co/QUxpVTGtFT

    Post summary

    The post announces a critical RCE vulnerability in OpenStack Vitrage’s query parser, detailing affected versions and the exploitation scenario, but does not provide a PoC, exploit code, or patch information.

    0000058
    119 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenstackvitrage---

Explore more