A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines.
Advisories
No advisories yet.
Fixes
Solution
Update to OpenNebula version 7.4.
Workaround
No workaround given by the vendor.
References
History
Tue, 01 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines. | |
| Title | Lack of authorisation in OpenNebula by OpenNebula Systems | |
| First Time appeared |
Opennebula Systems
Opennebula Systems opennebula |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:opennebula_systems:opennebula:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opennebula Systems
Opennebula Systems opennebula |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-01T12:17:49.009Z
Reserved: 2026-09-01T08:05:51.571Z
Link: CVE-2026-84165
No data.
Status : Received
Published: 2026-09-01T11:16:45.713
Modified: 2026-09-01T11:16:45.713
Link: CVE-2026-84165
No data.
OpenCVE Enrichment
Updated: 2026-09-01T12:30:04Z
Weaknesses