Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76878

Quick assessment

Affected
OpenStack Aodh
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 OpenStack Aodh 版本低于 22.0.1 的情况下,当查询参数 被设置为 时,告警列表 API 会绕过项目范围限制。该 API 仅检查 键是否存在,而未验证其值:当值为 时,会强制执行仅限管理员使用的策略;但当值为 时,API 会移除该键,并跳过通常用于将结果限制为调用者所属项目的逻辑分支。这导致具有 reader 角色的非管理员用户能够列出所有项目的告警信息,从而暴露包含信任网络钩子(trust webhook)URL、Heat 信号端点、项目 ID 和用户 ID 的告警操作信息。此外,该参数还可

CVSS 8.4 · High EPSS 0.48% · P39

Affected Version Matrix 3

VendorProduct Version RangeStatus
OpenStack Aodh 10.0.0< 20.0.1 affected
21.0.0< 21.0.1 affected
22.0.0< 22.0.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76878

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:H/SA:L
Source: CVE Program / CVE List V5
Vulnerability Type
使用不正确变量或索引作为参数的函数调用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenStack Aodh 10.0.0 ~ 20.0.1 -

II. Public POCs for CVE-2026-76878

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76878

登录查看更多情报信息。

Vendor Advisories for CVE-2026-76878 (3)

Mailing List Discussions for CVE-2026-76878 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-76878

No comments yet


Leave a comment