CVE-2026-55748: OS Command Injection
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/horizonto a version that resolves this vulnerability.Fixed in 25.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55748?
The severity of CVE-2026-55748 is classified as medium with a score of 6.
How do I fix CVE-2026-55748?
To address CVE-2026-55748, update to OpenStack Horizon version 25.7.4 or later.
What type of vulnerability is CVE-2026-55748?
CVE-2026-55748 is categorized under OS Command Injection vulnerabilities.
What are the potential impacts of CVE-2026-55748?
CVE-2026-55748 could allow an attacker to exploit shell metacharacters within project names, potentially leading to command injection.
Is CVE-2026-55748 considered a security vulnerability?
Some security experts view CVE-2026-55748 as a security hardening opportunity rather than a traditional vulnerability.