Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97404

Quick assessment

Affected
OpenStack Zaqar
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 OpenStack Zaqar 22.0.2 之前的版本中,WSGI 传输模块对 URL-Signature 请求头处理不当。攻击者只需发送一个带有空 URL-Signature 头部的请求,即可绕过 Keystone 身份验证和预签名 URL 验证。前提是攻击者知道目标项目的 UUID,且未进行身份认证,从而获得对该项目的队列、消息、声明(claims)和订阅(subscriptions)的读取、枚举、创建和删除权限。此外,若攻击者进一步获取管理员角色,还可能在启用 admin_mode 的部署环境中执行管理

CVSS 9.2 · Critical EPSS 0.27% · P17
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97404

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target project's UUID may bypass both Keystone authentication and pre-signed URL verification, resulting in the ability to read, enumerate, create, and delete that project's queues, messages, claims, and subscriptions. By additionally claiming an administrative role, the attacker may also perform administrative operations, such as managing pools and flavors in admin_mode deployments. Only deployments using the WSGI transport with an authentication strategy configured are affected; the websocket transport is not affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用不可信的源
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenStack Zaqar 1.0.0 ~ 20.1.2 -

II. Public POCs for CVE-2026-97404

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97404

请登录查看更多情报信息。

Other References for CVE-2026-97404 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-97404

No comments yet


Leave a comment