https://seclists.org/oss-sec/2026/q3/541: [OSSN-0108] Multiple authentication vulnerabilities in Ceph affecting OpenStack
Published Aug 20, 2026
·Updated
Affected Software
6 affected components
ceph Ceph<20.2.4, <19.2.6
Openstack Nova
Openstack Cinder
Openstack Glance
Openstack Manila
Ceph RADOS Gateway (RGW)
Frequently Asked Questions
1
Which deployments have the most practical exposure?
OpenStack clouds using RBD, RGW, or NFS are described as internally exposed, with the issue potentially allowing an insider to escalate privileges. Services holding CephX keyrings, including Nova, Cinder, Glance, and Manila, are at risk.
2
Can a Nova guest exploit this directly?
A Nova guest using Cinder RBD does not have access to the CephX key or Ceph storage network. The Nova host has that access, so the described risk is primarily to an insider with access to those resources.
3
What remediation is required?
Upgrade Ceph servers to Ceph 20.2.4 or 19.2.6, as applicable, and rotate CephX keyrings. All Ceph versions before 20.2.4 or 19.2.6 are listed as affected.
4
Do these issues affect data-at-rest encryption?
Data-at-rest encryption is not affected by CVE-2025-30156, but it is affected by CVE-2026-50152. Both issues are addressed by the updated releases.