CVE-2025-54955: Race Condition
OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54955?
CVE-2025-54955 is classified as a critical vulnerability due to its potential for full account takeover.
How can I fix CVE-2025-54955?
To mitigate CVE-2025-54955, upgrade to OpenNebula Community Edition version 7.0.0 or Enterprise Edition version 6.10.3 or later.
What types of systems are affected by CVE-2025-54955?
CVE-2025-54955 affects OpenNebula Community Edition versions prior to 7.0.0 and Enterprise Edition versions prior to 6.10.3.
Who can exploit CVE-2025-54955?
CVE-2025-54955 can be exploited by unauthenticated attackers to gain access to valid JSON Web Tokens belonging to legitimate users.
What is the impact of exploiting CVE-2025-54955?
Exploitation of CVE-2025-54955 can lead to unauthorized access and a complete takeover of user accounts in affected OpenNebula systems.