Get real-time updates on Telegram
CVE-2026-107363: Zaqar 1.0.0 to before 20.1.3, 21.0.0 to before 21.0.3, 22.0.0 to before 22.0.3, 23.0.0 to before 23.0.1
Affected technology
Zaqar · 1.0.0 to before 20.1.3, 21.0.0 to before 21.0.3, 22.0.0 to before 22.0.3, 23.0.0 to before 23.0.1
OpenStack
Description’s affected range: before 23.0.1
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
An authenticated user with a valid token for one project may substitute another project's UUID to enumerate, inspect, create, or delete queues belonging to that project, resulting in unauthorized disclosure, modification, or loss of queue data. Vendor/CNA’s CVSS 4.0 assessment (base score 6.1/10) rates confidentiality impact as low; integrity and availability impact as high.
- CWE
- CWE-472
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-08 01:09:29.465299+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-107363.html