https://seclists.org/oss-sec/2026/q3/255: [OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-66139)
Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Openstack Zaqar>=12.0.0<20.1.1, =21.0.0, =22.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-66139?
The severity of CVE-2026-66139 is rated as high due to the potential for unauthorized access.
2
How do I fix CVE-2026-66139?
To fix CVE-2026-66139, upgrade OpenStack Zaqar to version 20.1.1 or later.
3
What impact does CVE-2026-66139 have on OpenStack users?
CVE-2026-66139 allows attackers to bypass Keystone authentication, potentially compromising user data.
4
Which versions of OpenStack Zaqar are affected by CVE-2026-66139?
CVE-2026-66139 affects OpenStack Zaqar versions from 12.0.0 to 20.1.0.
5
Is there a workaround for CVE-2026-66139?
There are no documented workarounds for CVE-2026-66139; upgrading is the recommended solution.