CVE-2026-49299: [OSSA-2026-016] OpenStack Neutron: Errata 1 - Tagging policy bypass allows project aders to mutate tags (CVE-2026-49299)
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenStack Neutronto a version that resolves this vulnerability.Fixed in 28.0.1Patch OSSA-2026-016
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49299?
CVE-2026-49299 has a medium severity rating of 5.3 according to the CVSS.
How do I fix CVE-2026-49299?
Fixing CVE-2026-49299 involves upgrading to OpenStack Neutron version 28.0.1 or later to address the tagging policy mismatch.
What systems are affected by CVE-2026-49299?
CVE-2026-49299 affects OpenStack Neutron versions prior to 28.0.1.
What is the impact of CVE-2026-49299 on users?
CVE-2026-49299 allows project readers to create and update tags due to mismatched policy action names.
When was CVE-2026-49299 published?
CVE-2026-49299 was published on May 28, 2026.