Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 19 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Policy Misconfiguration Allows Unauthorized Tag Manipulation in OpenStack Neutron | openstack-neutron: OpenStack Neutron: Unauthorized tag modification due to policy enforcement mismatch |
| Weaknesses | CWE-425 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 29 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Policy Misconfiguration Allows Unauthorized Tag Manipulation in OpenStack Neutron |
Thu, 28 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected. | |
| First Time appeared |
Openstack
Openstack neutron |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:openstack:neutron:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack neutron |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-02T17:33:09.589Z
Reserved: 2026-05-28T21:53:02.642Z
Link: CVE-2026-49299
Updated: 2026-06-02T17:33:09.589Z
Status : Deferred
Published: 2026-05-28T22:17:02.093
Modified: 2026-06-02T20:16:39.760
Link: CVE-2026-49299
OpenCVE Enrichment
Updated: 2026-06-19T14:15:04Z