CVE-2026-66139: [OSSA-2026-029] OpenStack Zaqar: EXTRA-SPEC header bypasses Keystone authentication (CVE-2026-66139)
Published Jul 24, 2026
·Updated
OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
Affected Software
1 affected component
Openstack Zaqar<=22.0.0
Event History
Jul 24, 2026
CVE Published
via MITRE·04:14 AM
Data Sourced
via MITRE·04:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66139?
The severity of CVE-2026-66139 is medium with a score of 4.8.
2
What is CVE-2026-66139 about?
CVE-2026-66139 is an authentication bypass vulnerability in OpenStack Zaqar that occurs via an EXTRA-SPEC header when a UUID is known.
3
How does CVE-2026-66139 affect OpenStack Zaqar?
CVE-2026-66139 allows attackers to bypass authentication in OpenStack Zaqar, potentially gaining unauthorized access.
4
How do I fix CVE-2026-66139?
To remediate CVE-2026-66139, it is important to upgrade OpenStack Zaqar to version 22.0.1 or later.
5
What is the impact of CVE-2026-66139's vulnerability?
The impact of CVE-2026-66139 includes the possibility of unauthorized access due to authentication bypass.