Linuxsecurity Unauthorized Access Vulnerability in OpenStack Aodh and Watcher
Article Content
- •Vulnerability allows unauthorized access to sensitive data in OpenStack Aodh and Watcher.
- •Affected Ubuntu versions include 20.04, 22.04, 24.04, and 26.04.
- •Users must update to specific package versions and restart services to mitigate risks.
A serious vulnerability has been identified in OpenStack Aodh and Watcher, discovered by Chen YuXiang. The flaw allows unauthorized access to sensitive alarm metadata and the ability to trigger unauthorized action plans due to improper project scoping enforcement in the alarm list API and lack of authorization in the webhook trigger endpoint. This affects multiple Ubuntu LTS versions, including 20.04, 22.04, 24.04, and 26.04. Users are advised to update their systems to the specified package versions to mitigate the risk. After applying updates, a restart of the Aodh and Watcher services is required to implement the changes. The vulnerability has not been reported as in the wild.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which Ubuntu versions are affected?
What should I do to protect my systems?
Is there any evidence of active exploitation?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…