PYSEC-2026-2854
OpenStack Cyborg's Accelerator Request (ARQ) API does not enforce project ownership at any layer
Quick fix
PYSEC-2026-2854 — openstack-cyborg: upgrade to the fixed version with the command below.
pip install --upgrade 'openstack-cyborg>=16.0.1'Details
In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), database queries have no project filtering, and policy checks are self-referential (the authorize_wsgi decorator compares the caller's project_id with itself rather than the target resource). Any authenticated non-admin user can complete various actions such as deleting ARQs bound to other projects' instances, aka cross-tenant denial of service.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 16.0.1pip install --upgrade 'openstack-cyborg>=16.0.1'References
- https://nvd.nist.gov/vuln/detail/CVE-2026-40214[ADVISORY]
- https://bugs.launchpad.net/openstack-cyborg/+bug/2144056[WEB]
- https://github.com/openstack/cyborg[PACKAGE]
- https://security.openstack.org/ossa/OSSA-2026-011.html[WEB]
- https://www.openwall.com/lists/oss-security/2026/05/07/6[WEB]
- https://pypi.org/project/openstack-cyborg[PACKAGE]
- https://github.com/advisories/GHSA-mmpc-xjxr-5hf8[ADVISORY]