PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-74248 OpenStack CVE debrief

OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization, allowing an authenticated user to prevent deletion of a QoS policy by associating it with an amphora. This affects all Octavia deployments. The vulnerability has a medium severity level and requires verification of OpenStack Octavia deployment versions and configurations to prevent potential QoS policy deletion blockage. Defenders should assess their exposure and take necessary actions to prevent potential QoS policy deletion blockage. The issue is caused by the mishandling of QoS policy authorization, which can lead to unauthorized changes to QoS policies and potential security risks. TheCVE

Vendor
OpenStack
Product
Octavia
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-14
Original CVE updated
2026-09-09
Advisory published
2026-08-14
Advisory updated
2026-09-09

Who should care

OpenStack administrators, security teams, and IT professionals responsible for managing OpenStack Octavia deployments should assess their exposure and take necessary actions to prevent potential QoS policy deletion blockage.

Why it matters

CVE-2026-74248 is a medium-severity vulnerability in OpenStack Octavia that affects QoS policy authorization. Defenders should verify and update their deployments to prevent potential QoS policy deletion blockage.

  • Potential blockage of QoS policy deletion.
  • Unauthorized changes to QoS policies.
  • Need for verification of OpenStack Octavia deployment versions.
  • Potential security risks due to mishandled QoS policy authorization.

Technical summary

OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. An authenticated user can prevent deletion of a QoS policy by associating it with an amphora. This issue affects all Octavia deployments and requires verification of OpenStack Octavia deployment versions and configurations to prevent potential QoS policy deletion blockage. The vulnerability has a medium severity level and can lead to unauthorized changes to QoS policies and potential security risks due to mishandled QoS policy authorization. Defenders should verify and

Defensive priority

Defenders should prioritize verifying and updating OpenStack Octavia deployments to prevent potential QoS policy deletion blockage.

Recommended defensive actions

  • Verify OpenStack Octavia deployment versions and configurations.
  • Update OpenStack Octavia to a version that addresses the QoS policy authorization issue.
  • Review and restrict QoS policy associations with amphoras.
  • Monitor for potential unauthorized QoS policy changes.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the scope of affected versions and potential impact requires further verification from official OpenStack sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-74248 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-74248

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-74248 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74248

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.