NONE · 0

CVE-2026-49299

In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names ev...

Vulnerability Description

In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-49299?

CVE-2026-49299 is a documented vulnerability. In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names ev...

How severe is CVE-2026-49299?

CVSS scoring is not yet available for CVE-2026-49299. Check NVD for updates.

Is there a patch for CVE-2026-49299?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.