CVE-2026-28370: [OSSA-2026-003] OpenStack Vitrage: mote code execution through Vitrage query parser (CVE-2026-28370)
In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of the Vitrage service. All deployments exposing the Vitrage API are affected. This occurs in createqueryfunction in vitrage/graph/query.py.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28370?
CVE-2026-28370 has been classified with a high severity due to the potential for remote code execution.
How do I fix CVE-2026-28370?
To resolve CVE-2026-28370, upgrade OpenStack Vitrage to version 12.0.1 or later, or version 13.0.1 or later.
What versions of OpenStack Vitrage are affected by CVE-2026-28370?
CVE-2026-28370 affects OpenStack Vitrage versions prior to 12.0.1, 13.0.0, 14.0.0, and 15.0.0.
What type of vulnerability is CVE-2026-28370?
CVE-2026-28370 is a remote code execution vulnerability in the query parser of OpenStack Vitrage.
Who is at risk from CVE-2026-28370?
Users with access to the Vitrage API are at risk of triggering code execution on the Vitrage service host due to CVE-2026-28370.