CVE-2026-55707

Source
https://cve.org/CVERecord?id=CVE-2026-55707
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55707.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-55707
Downstream
Published
2026-08-05T04:44:16Z
Modified
2026-09-14T03:45:47Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers.

Database specific
{
    "cna_assigner": "mitre",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55707.json"
}
References

Affected packages

Git / opendev.org/openstack/neutron

Affected ranges

Type
GIT
Repo
https://opendev.org/openstack/neutron
Events
Introduced
3c6be2d1a2cba28e5aee75be2e37ef55b0c2a5ea
Fixed
9ebdbc328d6fe7ed0fffe454951b4d041188e69b
Introduced
46f4ef447537d80bff2bb64da6a61fff40e8fcc3
Fixed
e415739e74bc7a48a5b8801a40883ea873007949
Introduced
eb9dd526a3c4ba0ffbb69d06cc387c86ca755d42
Fixed
d87ec8ef84f76a1fdd501cb70bef519c3b82e7b1
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "14.0.0"
        },
        {
            "fixed": "26.0.6"
        },
        {
            "introduced": "27.0.0"
        },
        {
            "fixed": "27.0.4"
        },
        {
            "introduced": "28.0.0"
        },
        {
            "fixed": "28.0.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

14.*
14.0.0
14.0.0.0rc1
15.*
15.0.0.0b1
15.0.0.0rc1
16.*
16.0.0.0b1
16.0.0.0rc1
17.*
17.0.0.0rc1
18.*
18.0.0.0rc1
19.*
19.0.0.0rc1
20.*
20.0.0.0rc1
21.*
21.0.0.0rc1
22.*
22.0.0.0rc1
23.*
23.0.0.0b1
23.0.0.0b2
23.0.0.0b3
23.0.0.0rc1
24.*
24.0.0.0b1
24.0.0.0rc1
25.*
25.0.0.0b1
25.0.0.0rc1
26.*
26.0.0
26.0.0.0b1
26.0.0.0b2
26.0.0.0rc1
26.0.0.0rc2
26.0.1
26.0.2
26.0.3
26.0.4
26.0.5
27.*
27.0.0
27.0.0.0rc1
27.0.1
27.0.2
27.0.3
28.*
28.0.0
28.0.0.0rc2
28.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55707.json"