Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-84165— Lack of authorisation in OpenNebula by OpenNebula Systems

Quick assessment

Affected
OpenNebula Systems OpenNebula
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenNebula(由 OpenNebula Systems 开发)存在一个与访问控制不当相关的漏洞,影响所有 7.4 之前的版本。该漏洞允许拥有基本权限的已认证用户通过 函数,在其他用户的虚拟机上执行命令,而系统未对访问权限进行充分校验。利用该漏洞只需知道目标虚拟机的标识符,且该虚拟机上启用了 qemu-agent。成功利用后,攻击者可以执行任意命令,从而危及受影响虚拟机的机密性、完整性和可用性。

CVSS 8.7 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84165

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Lack of authorisation in OpenNebula by OpenNebula Systems
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenNebula Systems OpenNebula 0 ~ 7.4 -

II. Public POCs for CVE-2026-84165

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84165

登录查看更多情报信息。

Other References for CVE-2026-84165 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-84165

No comments yet


Leave a comment