Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-97404: OpenStack Zaqar allows unauthenticated queue access

CVE-2026-97404 · published 15 days ago
Summary

OpenStack Zaqar versions before 22.0.2 on Debian can be tricked into accepting an empty signature header. An attacker who knows a project’s ID can then read, create, modify, or delete that project's queues and messages without logging in, and may even gain admin rights in certain setups. Upgrade Zaqar to version 22.0.2 or later, or change the transport configuration to avoid using the vulnerable WSGI mode.

What to do
  • Update debian zaqar to version 23.0.0~rc1-3.
  • Update openstack zaqar to version 20.1.2 or later.
Affected software
Ecosystem VendorProductAffected versions
– openstack zaqar < 20.1.2
Debian:12 debian zaqar All versions
Ubuntu:16.04:LTS canonical zaqar All versions
Debian:14 debian zaqar < 23.0.0~rc1-3
Fix: upgrade to 23.0.0~rc1-3
Original advisory text
DEBIAN-CVE-2026-97404
In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target project's UUID may bypass both Keystone authentication and pre-signed URL verification, resulting in the ability to read, enumerate, create, and delete that project's queues, messages, claims, and subscriptions. By additionally claiming an administrative role, the attacker may also perform administrative operations, such as managing pools and flavors in admin_mode deployments. Only deployments using the WSGI transport with an authentication strategy configured are affected; the websocket transport is not affected.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-348Use of Less Trusted Source
Timeline
Published24 Sep 2026
Updated9 Oct 2026
First seen24 Sep 2026
Track software like this
Free during beta