https://seclists.org/oss-sec/2026/q2/817: [OSSA-2026-021] OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shad networks (CVE-2026-pending)
Published Jun 4, 2026
·Updated
Affected Software
1 affected component
Openstack Neutron>=25.0.0<25.2.4, >=26.0.0<26.0.4, >=27.0.0<27.0.3, =28.0.0
Frequently Asked Questions
1
What is the severity of OSSA-2026-021?
OSSA-2026-021 has been classified as a high severity vulnerability, as it allows project managers to bypass RBAC policies.
2
How do I fix OSSA-2026-021?
To fix OSSA-2026-021, it is recommended to upgrade to the latest version of OpenStack Neutron that addresses this vulnerability.
3
What systems are affected by OSSA-2026-021?
OSSA-2026-021 affects all versions of OpenStack Neutron prior to the latest patch that resolves the RBAC policy bypass issue.
4
What implications does OSSA-2026-021 have for users?
Users of OpenStack Neutron may face unauthorized access and control over trusted devices on shadow networks due to the RBAC policy bypass inherent in OSSA-2026-021.
5
When was OSSA-2026-021 published?
OSSA-2026-021 was published on June 4, 2026.