OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 14 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Octavia QoS Policy Authorization Bypass Preventing Policy Deletion |
Fri, 14 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected. | |
| First Time appeared |
Openstack
Openstack octavia |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:openstack:octavia:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack octavia |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-14T20:20:31.446Z
Reserved: 2026-08-14T20:20:31.038Z
Link: CVE-2026-74248
No data.
Status : Received
Published: 2026-08-14T21:17:58.173
Modified: 2026-08-14T21:17:58.173
Link: CVE-2026-74248
No data.
OpenCVE Enrichment
Updated: 2026-08-14T21:30:04Z
Weaknesses