Re: [OSSA-2026-043] OpenStack Zaqar: Zaqar WebSocket project substitution allows cross-project queue access (CVE-2026-107363) errata 1
OpenStack assigned CVE-2026-107363 to a Zaqar WebSocket flaw enabling cross-project queue access.
OpenStack published errata 1 for OSSA-2026-043, assigning CVE-2026-107363 to a Zaqar WebSocket flaw. Project substitution in the WebSocket interface can let a user access queues belonging to another project. The issue affects Zaqar from version 1.0.0 before 20.1.3. The notice does not report exploitation.
- CVE-2026-107363 is assigned to OpenStack Zaqar WebSocket project substitution.
- The flaw allows cross-project queue access.
- Affected releases are Zaqar 1.0.0 up to, but not including, 20.1.3.
- Errata 1 attaches the CVE to advisory OSSA-2026-043.
Vulnerabilities mentionedAll →
- CVE-2026-1073636.1—Cross-project queue access in OpenStack Zaqar WebSocketpublished · OpenStack Zaqar
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-107363 | Cross-project queue access in OpenStack Zaqar WebSocket OpenStack Zaqar before 23.0.1 fails, on its WebSocket transport, to bind later requests to the project authenticated by the Keystone token. An authenticated user who already holds a valid token for one project can substitute another project's UUID and then enumerate, inspect, create, or delete that project's queues, which can disclose, modify, or destroy queue data. Only deployments that use the WebSocket transport together with Keystone authentication are affected. No public proof-of-concept is known, the issue is not in CISA KEV, and the related notice is the OpenStack advisory OSSA-2026-043. Do: Upgrade OpenStack Zaqar to 23.0.1 or later. Until that is done, disable the WebSocket transport (or stop using it with Keystone) and review access logs for requests whose project UUID does not match the project bound to the Keystone token. Confirm the deployment actually uses WebSocket with Keystone before treating this as in scope; other transports are not described as affected. |
Posted by Goutham Pacha Ravi on Oct 07 Errata 1 for OSSA-2026-043: CVE-2026-107363 has been assigned for this vulnerability. ===================================================================================== OSSA-2026-043: Zaqar WebSocket project substitution allows cross-project queue access ===================================================================================== :Date: October 07, 2026 :CVE: CVE-2026-107363 Affects ~~~~~~~ - Zaqar: >=1.0.0 <20.1.3,...
This source does not provide full text. Read it at seclists.org.