CVE-2026-40214Disclosure

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares the caller's project_id with itself rather than the target resource). Any authenticated non-admin user can complete various actions such as deleting ARQs bound to other projects' instances, aka cross-tenant denial of service.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-282

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-09); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-09: 1Mentions · 2026-06-09: 1Patch / Workaround · 2026-06-09: 1Technical Details · 2026-05-09: 1Technical Details · 2026-06-09: 105-0906-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    OSSA-2026-011: OpenStack Cyborg: Multiple access control vulnerabilities in Cyborg accelerator management https://www.openwall.com/lists/oss-security/2026/05/07/6 CVE-2026-40213 (policy bypass) affects 5.0.0 and later CVE-2026-40214 (missing ownership) affects 3.0.0 and later

    Post summary

    The message announces two access‑control CVEs in OpenStack Cyborg accelerator management, specifying affected versions and vulnerability types, but it provides no PoC, exploit, active exploitation, patch, or debunking details.

    00031648
    4.7K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    Two Cyborg API flaws CVE-2026-40213 and CVE-2026-40214 allow authenticated users to delete cross-tenant ARQs and reprogramme FPGA bitstreams on Ubuntu 26.04 LTS and 25.10, Ubuntu disclosed in security notice USN-8413-1. https://threatcluster.io/cluster/critical-vulnerabilities-in-cyborg-api-affect-ubuntu-users-d69c7db9

    Post summary

    The text announces two authenticated‑user vulnerabilities in Cyborg API that permit deletion of cross‑tenant ARQs and reprogramming of FPGA bitstreams, referencing a vendor security notice that presumably contains a patch.

    0000045
    318 followersView on X

Explore more