PatchSiren cyber security CVE debrief
CVE-2026-74248 OpenStack CVE debrief
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization, allowing an authenticated user to prevent deletion of a QoS policy by associating it with an amphora. This affects all Octavia deployments. The vulnerability has a medium severity level and requires verification of OpenStack Octavia deployment versions and configurations to prevent potential QoS policy deletion blockage. Defenders should assess their exposure and take necessary actions to prevent potential QoS policy deletion blockage. The issue is caused by the mishandling of QoS policy authorization, which can lead to unauthorized changes to QoS policies and potential security risks. TheCVE
- Vendor
- OpenStack
- Product
- Octavia
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-14
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-14
- Advisory updated
- 2026-09-09
Who should care
OpenStack administrators, security teams, and IT professionals responsible for managing OpenStack Octavia deployments should assess their exposure and take necessary actions to prevent potential QoS policy deletion blockage.
Why it matters
CVE-2026-74248 is a medium-severity vulnerability in OpenStack Octavia that affects QoS policy authorization. Defenders should verify and update their deployments to prevent potential QoS policy deletion blockage.
- Potential blockage of QoS policy deletion.
- Unauthorized changes to QoS policies.
- Need for verification of OpenStack Octavia deployment versions.
- Potential security risks due to mishandled QoS policy authorization.
Technical summary
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. An authenticated user can prevent deletion of a QoS policy by associating it with an amphora. This issue affects all Octavia deployments and requires verification of OpenStack Octavia deployment versions and configurations to prevent potential QoS policy deletion blockage. The vulnerability has a medium severity level and can lead to unauthorized changes to QoS policies and potential security risks due to mishandled QoS policy authorization. Defenders should verify and
Defensive priority
Defenders should prioritize verifying and updating OpenStack Octavia deployments to prevent potential QoS policy deletion blockage.
Recommended defensive actions
- Verify OpenStack Octavia deployment versions and configurations.
- Update OpenStack Octavia to a version that addresses the QoS policy authorization issue.
- Review and restrict QoS policy associations with amphoras.
- Monitor for potential unauthorized QoS policy changes.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the scope of affected versions and potential impact requires further verification from official OpenStack sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-74248 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-74248
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-74248 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74248
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://bugs.launchpad.net/octavia/+bug/2161500
-
Source reference
Unverified legacy reference
URL: https://www.openwall.com/lists/oss-security/2026/08/13/12
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.