CVE-2026-40213: [OSSA-2026-011] OpenStack Cyborg: Multiple access control vulnerabilities in Cyborg accelerator management (CVE-2026-40213, CVE-2026-40214)
Last updated 9 June 2026
Other sources
OpenStack Cyborg before 16.0.1 uses rule:allow (checkstr='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40213?
CVE-2026-40213 is considered a critical vulnerability due to its impact on access control in OpenStack Cyborg.
How do I fix CVE-2026-40213?
To fix CVE-2026-40213, upgrade OpenStack Cyborg to version 16.0.1 or later.
What are the implications of CVE-2026-40213?
CVE-2026-40213 allows unauthorized access to multiple API endpoints in OpenStack Cyborg, potentially leading to data breaches.
Which versions of OpenStack Cyborg are affected by CVE-2026-40213?
OpenStack Cyborg versions before 16.0.1 are affected by CVE-2026-40213.
Is CVE-2026-40213 related to any other vulnerabilities?
Yes, CVE-2026-40213 is related to CVE-2026-40214, both concerning access control issues in OpenStack Cyborg.