CVE-2026-74248: Medium severity Openstack Octavia vulnerability
Published Aug 14, 2026
·Updated
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.
Affected Software
1 affected component
Openstack Octavia<=18.0.0
Event History
Aug 14, 2026
CVE Published
via MITRE·08:20 PM
Data Sourced
via MITRE·08:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-74248?
The severity of CVE-2026-74248 is medium, rated at 4.3.
2
What are the risks associated with CVE-2026-74248?
CVE-2026-74248 allows an authenticated user to prevent the deletion of a QoS policy by associating it with an amphora.
3
How do I fix CVE-2026-74248?
To fix CVE-2026-74248, ensure you apply the latest patches and updates for OpenStack Octavia.
4
Who is affected by CVE-2026-74248?
All OpenStack Octavia deployments are affected by CVE-2026-74248.
5
What versions of OpenStack Octavia are impacted by CVE-2026-74248?
CVE-2026-74248 affects OpenStack Octavia versions up to and including 18.0.0.