Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-97404: OpenStack Zaqar allows unauthenticated queue access
CVE-2026-97404 · published 15 days ago
Summary
OpenStack Zaqar versions before 22.0.2 on Debian can be tricked into accepting an empty signature header. An attacker who knows a project’s ID can then read, create, modify, or delete that project's queues and messages without logging in, and may even gain admin rights in certain setups. Upgrade Zaqar to version 22.0.2 or later, or change the transport configuration to avoid using the vulnerable WSGI mode.
What to do
- Update debian zaqar to version 23.0.0~rc1-3.
- Update openstack zaqar to version 20.1.2 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | openstack | zaqar | < 20.1.2 |
| Debian:12 | debian | zaqar | All versions |
| Ubuntu:16.04:LTS | canonical | zaqar | All versions |
| Debian:14 | debian | zaqar |
< 23.0.0~rc1-3 Fix: upgrade to 23.0.0~rc1-3
|
Original advisory text
DEBIAN-CVE-2026-97404
In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target project's UUID may bypass both Keystone authentication and pre-signed URL verification, resulting in the ability to read, enumerate, create, and delete that project's queues, messages, claims, and subscriptions. By additionally claiming an administrative role, the attacker may also perform administrative operations, such as managing pools and flavors in admin_mode deployments. Only deployments using the WSGI transport with an authentication strategy configured are affected; the websocket transport is not affected.
References
- https://launchpad.net/bugs/2164987
- https://security-tracker.debian.org/tracker/CVE-2026-97404 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-97404 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-97404 Third Party Advisory
- https://security.openstack.org/ossa/OSSA-2026-042.html Third Party Advisory
- http://www.openwall.com/lists/oss-security/2026/09/24/6
- https://opendev.org/openstack/zaqar URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97404... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-97404 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.2
Critical
Type
CWE-348Use of Less Trusted Source
Timeline
Published24 Sep 2026
Updated9 Oct 2026
First seen24 Sep 2026
Sources
CVE-2026-97404 · NVD
CVE-2026-97404 · MITRE
DEBIAN-CVE-2026-97404 · OSV
UBUNTU-CVE-2026-97404 · OSV
CVE-2026-97404 · OSV
Track software like this
Free during beta