https://seclists.org/oss-sec/2026/q2/723: [OSSA-2026-016] OpenStack Neutron: Tagging policy bypass allows project aders to mutate tags (CVE-2026-pending)
Published May 28, 2026
·Updated
Affected Software
1 affected component
Openstack Neutron>=26.0.0<26.0.4, >=27.0.0<27.0.3, >=28.0.0<28.0.1
Frequently Asked Questions
1
What is the severity of CVE-2026-pending?
CVE-2026-pending has a high severity rating due to its potential impact on project tagging policies.
2
How do I fix CVE-2026-pending?
To mitigate CVE-2026-pending, upgrade to OpenStack Neutron version 26.0.4, 27.0.3, or 28.0.1 and above.
3
What versions of OpenStack Neutron are affected by CVE-2026-pending?
CVE-2026-pending affects OpenStack Neutron versions 26.0.0 to <26.0.4, 27.0.0 to <27.0.3, and 28.0.0 to <28.0.1.
4
What kind of vulnerability is CVE-2026-pending?
CVE-2026-pending is a tagging policy bypass vulnerability that allows project leaders to mutate tags improperly.
5
Is there a workaround for CVE-2026-pending?
There are no known workarounds for CVE-2026-pending; updating to the patched versions is necessary.