https://seclists.org/oss-sec/2026/q2/428: [OSSA-2026-011] OpenStack Cyborg: Multiple access control vulnerabilities in Cyborg accelerator management (CVE-2026-40213, CVE-2026-40214)
Published May 7, 2026
·Updated
Affected Software
1 affected component
Openstack Cyborg>=3.0.0<14.0.1, >=15.0.0<15.0.1, >=16.0.0<16.0.1
Frequently Asked Questions
1
What are the access control vulnerabilities related to CVE-2026-40213 and CVE-2026-40214?
CVE-2026-40213 and CVE-2026-40214 are multiple access control vulnerabilities in OpenStack Cyborg that could allow unauthorized access to accelerator management features.
2
What versions of OpenStack Cyborg are affected by CVE-2026-40213 and CVE-2026-40214?
CVE-2026-40213 and CVE-2026-40214 affect Cyborg versions >=3.0.0 <14.0.1, >=15.0.0 <15.0.1, and >=16.0.0 <16.0.1.
3
What is the severity of CVE-2026-40213?
The severity of CVE-2026-40213 is classified as high due to the potential exploitation risk associated with unauthorized access.
4
How can I fix CVE-2026-40213 and CVE-2026-40214?
To fix CVE-2026-40213 and CVE-2026-40214, upgrade OpenStack Cyborg to a version that is not affected, specifically 14.0.1 or later, 15.0.1 or later, or 16.0.1 or later.
5
What impact could CVE-2026-40214 have on my OpenStack environment?
CVE-2026-40214 could potentially allow attackers to gain unauthorized access to sensitive resources, compromising the security of your OpenStack environment.