CVE-2026-74248: [OSSA-2026-035] OpenStack Octavia: Unauthorized QoS policy deletion lock (CVE-2026-74248) errata 1
Last updated 24 September 2026
Other sources
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/octaviato a version that resolves this vulnerability.Fixed in 18.0.0-4Fixed in 19.0.0~rc1-2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74248?
The severity of CVE-2026-74248 is medium, rated at 4.3.
What are the risks associated with CVE-2026-74248?
CVE-2026-74248 allows an authenticated user to prevent the deletion of a QoS policy by associating it with an amphora.
How do I fix CVE-2026-74248?
To fix CVE-2026-74248, ensure you apply the latest patches and updates for OpenStack Octavia.
Who is affected by CVE-2026-74248?
All OpenStack Octavia deployments are affected by CVE-2026-74248.
What versions of OpenStack Octavia are impacted by CVE-2026-74248?
CVE-2026-74248 affects OpenStack Octavia versions up to and including 18.0.0.