PYSEC-2026-2678

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/neutron/PYSEC-2026-2678.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-2678
Aliases
Published
2026-07-13T15:19:13Z
Modified
2026-07-13T16:32:15Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenStack Neutron has an Incorrect Authorization issue
Details

In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.

References

Affected packages

PyPI / neutron

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
26.0.0
Fixed
26.0.4
Introduced
27.0.0
Fixed
27.0.3
Introduced
28.0.0
Fixed
28.0.1

Affected versions

26.*
26.0.0
26.0.1
26.0.2
26.0.3
27.*
27.0.0
27.0.1
27.0.2
28.*
28.0.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/neutron/PYSEC-2026-2678.yaml"