Skip to content
Unauthorized Access Vulnerability in OpenStack Aodh and Watcher

Unauthorized Access Vulnerability in OpenStack Aodh and Watcher

First seen 6 Oct 2026, 09:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 11:27 UTC
  • •Vulnerability allows unauthorized access to sensitive data in OpenStack Aodh and Watcher.
  • •Affected Ubuntu versions include 20.04, 22.04, 24.04, and 26.04.
  • •Users must update to specific package versions and restart services to mitigate risks.

A serious vulnerability has been identified in OpenStack Aodh and Watcher, discovered by Chen YuXiang. The flaw allows unauthorized access to sensitive alarm metadata and the ability to trigger unauthorized action plans due to improper project scoping enforcement in the alarm list API and lack of authorization in the webhook trigger endpoint. This affects multiple Ubuntu LTS versions, including 20.04, 22.04, 24.04, and 26.04. Users are advised to update their systems to the specified package versions to mitigate the risk. After applying updates, a restart of the Aodh and Watcher services is required to implement the changes. The vulnerability has not been reported as in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-05
Vulnerability disclosed
Chen YuXiang discovered a flaw in OpenStack Aodh and Watcher affecting multiple Ubuntu LTS versions.
Linuxsecurity
2026-10-05
Patch released
Ubuntu released updates for OpenStack Aodh and Watcher to address the vulnerability.
Ubuntu

More articles in this cluster (4)

Following this threat?

Track Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which Ubuntu versions are affected?
The vulnerability affects Ubuntu 20.04, 22.04, 24.04, and 26.04 LTS.
What should I do to protect my systems?
Update to the specified package versions for OpenStack Aodh and Watcher and restart the services.
Is there any evidence of active exploitation?
No evidence of active exploitation has been reported for this vulnerability.