CVE-2026-40213Disclosure

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-09); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-09: 1Mentions · 2026-06-09: 1Patch / Workaround · 2026-06-09: 1Technical Details · 2026-05-09: 1Technical Details · 2026-06-09: 105-0906-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    OSSA-2026-011: OpenStack Cyborg: Multiple access control vulnerabilities in Cyborg accelerator management https://www.openwall.com/lists/oss-security/2026/05/07/6 CVE-2026-40213 (policy bypass) affects 5.0.0 and later CVE-2026-40214 (missing ownership) affects 3.0.0 and later

    Post summary

    An OpenStack Cyborg security advisory announces two access‑control issues—policy bypass and missing ownership—affecting recent versions, without any PoC, exploit, or patch details supplied.

    00031648
    4.7K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    Two Cyborg API flaws CVE-2026-40213 and CVE-2026-40214 allow authenticated users to delete cross-tenant ARQs and reprogramme FPGA bitstreams on Ubuntu 26.04 LTS and 25.10, Ubuntu disclosed in security notice USN-8413-1. https://threatcluster.io/cluster/critical-vulnerabilities-in-cyborg-api-affect-ubuntu-users-d69c7db9

    Post summary

    The post announces two CVE vulnerabilities in the Cyborg API that let authenticated users delete cross‑tenant ARQs and reprogram FPGA bitstreams on Ubuntu 26.04 LTS and 25.10, referencing a vendor security notice.

    0000045
    318 followersView on X

Explore more