CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-107363: Zaqar 1.0.0 to before 20.1.3, 21.0.0 to before 21.0.3, 22.0.0 to before 22.0.3, 23.0.0 to before 23.0.1

Affected technology

Zaqar · 1.0.0 to before 20.1.3, 21.0.0 to before 21.0.3, 22.0.0 to before 22.0.3, 23.0.0 to before 23.0.1
OpenStack

Description’s affected range: before 23.0.1

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

An authenticated user with a valid token for one project may substitute another project's UUID to enumerate, inspect, create, or delete queues belonging to that project, resulting in unauthorized disclosure, modification, or loss of queue data. Vendor/CNA’s CVSS 4.0 assessment (base score 6.1/10) rates confidentiality impact as low; integrity and availability impact as high.

Published

CWE
CWE-472
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-107363.html