As per upstream announce: https://security.openstack.org/ossa/OSSA-2026-036.html Date: August 19, 2026 CVE: CVE-2026-pending Affects: Aodh: >=10.0.0 <20.0.1, ==21.0.0, ==22.0.0 Watcher: >=4.0.0 <14.1.2, >=15.0.0 <15.1.2, >=16.0.0 <16.0.2 Description: Chen YuXiang of the Institute of Computing Technology, Chinese Academy of Sciences reported that OpenStack Aodh does not enforce project scope on the alarm listing API when the all_projects query parameter is supplied with a false value. A non-admin user holding only the reader role can list alarms belonging to other projects, optionally targeting a specific project, exposing alarm metadata such as webhook action URLs, signal endpoints, and project identifiers. All Aodh deployments are affected. The same reporter found that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit’s webhook URL, for example from the Aodh alarm metadata leaked above, can start an EVENT audit and its associated action plan regardless of their own project or role. All Watcher deployments are affected. Patches: https://review.opendev.org/1001503 (2025.1/epoxy (aodh)) https://review.opendev.org/1001509 (2025.1/epoxy (watcher)) https://review.opendev.org/1001502 (2025.2/flamingo (aodh)) https://review.opendev.org/1001508 (2025.2/flamingo (watcher)) https://review.opendev.org/1001501 (2026.1/gazpacho (aodh)) https://review.opendev.org/1001507 (2026.1/gazpacho (watcher)) https://review.opendev.org/1001500 (2026.2/hibiscus (development) (aodh)) https://review.opendev.org/1001505 (2026.2/hibiscus (development) (watcher)) Credits: Chen YuXiang from Institute of Computing Technology, Chinese Academy of Sciences References: https://launchpad.net/bugs/2161276 https://launchpad.net/bugs/2161771 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending Notes: A CVE identifier was requested from MITRE for the aodh vulnerability on 2026-08-03. The CVE will be added to this advisory by errata once assigned.
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/4d789b90c510a3b307eb51a16f2f3b41d47523b9 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-03X: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/14394ae17f71b082e377d52c0ca85ae36bc44f0e ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/6f1b305736cd0479566ba1b0cd847ae575e68522 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/55d0ed2c02f704414497fa9497ffb23f6e69c624 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/59004027185a6cf3fd1a977fbe25a724f41ecb89 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/8060a3e724ee38434e9c4a8ca02220b27e2c29b4 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/16ac30ff691c87edcdda6387daa85c1897c09329 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/ecc9aacc731c43f79e4f1732198716a28a0d565a ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/f75635916b4a82ef228e26a55be12a6110ef6520 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-03X: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/bf70f41c2fe696c3f77528f5b4c7d88286955cfc ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/834a4c76e9a2eab4b24f142e95c4da2d2492d7ff ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/30156bfdfc26b52508040071775e264bca8ffef2 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/dd7dad460101fe59ec054c2282daab5fad3627a1 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/0e38cd1e64d306560871ff47d745fe80545d69d4 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/1655783ff5f99bbcf4ec75cda0cd8ab7253bf64c ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/0f6bf58aa69cbd8405bfe7646e97c6bde2a46570 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/676d77b113265abc78b717952d20f79377b08d95 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/a07bc19294568ba5ecc2b5b250288dc472a8fe78 ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879
Hello, Bug #1144879 in aodh reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/aodh/-/commit/a942af5aa2fe12d2f9367752ff508c16d6a2ea8b ------------------------------------------------------------------------ * CVE-2026-76878 / OSSA-2026-036: Aodh does not correctly enforce project scope when the all_projects query parameter is present with a false value. A non-admin project reader can list alarms belonging to other projects by passing all_projects=false in a list query, optionally combined with a foreign project_id to target a specific project. Leaked alarm data includes trust webhook URLs, Heat signal endpoints, and project identifiers. Applied upstream patch: "Fix all_projects=false bypass project scope" (Closes: #1144879). ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144879