#1144880 OSSA-2026-036: Watcher webhook authorization bypass

Package:
src:watcher
Source:
src:watcher
Submitter:
Thomas Goirand
Date:
2026-08-20 07:49:03 UTC
Severity:
normal
Tags:
#1144880#5
Date:
2026-08-19 19:10:01 UTC
From:
To:
As per upstream announce at:
https://security.openstack.org/ossa/OSSA-2026-036.html


Date:
    August 19, 2026

CVE:
    CVE-2026-pending

Affects:
    Aodh: >=10.0.0 <20.0.1, ==21.0.0, ==22.0.0
    Watcher: >=4.0.0 <14.1.2, >=15.0.0 <15.1.2, >=16.0.0 <16.0.2

Description:

Chen YuXiang of the Institute of Computing Technology, Chinese Academy of
Sciences reported that OpenStack Aodh does not enforce project scope on the
alarm listing API when the all_projects query parameter is supplied with a
false value. A non-admin user holding only the reader role can list alarms
belonging to other projects, optionally targeting a specific project, exposing
alarm metadata such as webhook action URLs, signal endpoints, and project
identifiers. All Aodh deployments are affected.

The same reporter found that OpenStack Watcher does not apply authorization to
its webhook trigger endpoint. Any authenticated user who learns an audit’s
webhook URL, for example from the Aodh alarm metadata leaked above, can start
an EVENT audit and its associated action plan regardless of their own project
or role. All Watcher deployments are affected.

Patches:
https://review.opendev.org/1001503 (2025.1/epoxy (aodh))
https://review.opendev.org/1001509 (2025.1/epoxy (watcher))
https://review.opendev.org/1001502 (2025.2/flamingo (aodh))
https://review.opendev.org/1001508 (2025.2/flamingo (watcher))
https://review.opendev.org/1001501 (2026.1/gazpacho (aodh))
https://review.opendev.org/1001507 (2026.1/gazpacho (watcher))
https://review.opendev.org/1001500 (2026.2/hibiscus (development) (aodh))
https://review.opendev.org/1001505 (2026.2/hibiscus (development) (watcher))

Credits:
    Chen YuXiang from Institute of Computing Technology, Chinese Academy of
Sciences

References:
https://launchpad.net/bugs/2161276
https://launchpad.net/bugs/2161771
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending

Notes:
    A CVE identifier was requested from MITRE for the aodh vulnerability on
2026-08-03. The CVE will be added to this advisory by errata once assigned.

#1144880#8
Date:
2026-08-19 20:42:28 UTC
From:
To:
Hello,

Bug #1144880 in watcher reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/watcher/-/commit/dcbdf5acf728979c3e70a4609dd26acca6d6d62b
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-036: Watcher webhook trigger endpoint does not
    enforce oslo.policy authorization. Any authenticated user who learns a
    Watcher audit webhook URL can POST to the webhook to trigger an
    administrator-owned EVENT audit and its associated action plan, regardless
    of the caller's project or role. The webhook endpoint has lacked policy
    enforcement since its introduction in the Ussuri release. Applied upstream
    patch: "Add policy enforcement to webhook trigger endpoint".
    (Closes: #1144880)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144880

#1144880#13
Date:
2026-08-19 20:45:57 UTC
From:
To:
Hello,

Bug #1144880 in watcher reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/watcher/-/commit/58877652150a4f55e2e88e4618df94da2f207e3f
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-036: Watcher webhook trigger endpoint does not
    enforce oslo.policy authorization. Any authenticated user who learns a
    Watcher audit webhook URL can POST to the webhook to trigger an
    administrator-owned EVENT audit and its associated action plan, regardless
    of the caller's project or role. The webhook endpoint has lacked policy
    enforcement since its introduction in the Ussuri release. Applied upstream
    patch: "Add policy enforcement to webhook trigger endpoint".
    (Closes: #1144880)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144880

#1144880#16
Date:
2026-08-19 20:58:21 UTC
From:
To:
Hello,

Bug #1144880 in watcher reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/watcher/-/commit/eb7cb11a5cc3bc705e6c29844ee1fe193f73780d
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-036: Watcher webhook trigger endpoint does not
    enforce oslo.policy authorization. Any authenticated user who learns a
    Watcher audit webhook URL can POST to the webhook to trigger an
    administrator-owned EVENT audit and its associated action plan, regardless
    of the caller's project or role. The webhook endpoint has lacked policy
    enforcement since its introduction in the Ussuri release. Applied upstream
    patch: "Add policy enforcement to webhook trigger endpoint".
    (Closes: #1144880)
  * Added python3-ddt as build-depends, needed for this patch.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144880

#1144880#19
Date:
2026-08-19 21:04:22 UTC
From:
To:
Hello,

Bug #1144880 in watcher reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/watcher/-/commit/9ed5bff13967ac096c3c548d1e865a6b0bbfe167
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-036: Watcher webhook trigger endpoint does not
    enforce oslo.policy authorization. Any authenticated user who learns a
    Watcher audit webhook URL can POST to the webhook to trigger an
    administrator-owned EVENT audit and its associated action plan, regardless
    of the caller's project or role. The webhook endpoint has lacked policy
    enforcement since its introduction in the Ussuri release. Applied upstream
    patch: "Add policy enforcement to webhook trigger endpoint".
    (Closes: #1144880)
  * Add python3-ddt as build-depends, needed for this patch.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144880

#1144880#22
Date:
2026-08-19 21:05:20 UTC
From:
To:
Hello,

Bug #1144880 in watcher reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/watcher/-/commit/aa1a0808c309bd1d697c85b3b4e001fa09425b03
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-036: Watcher webhook trigger endpoint does not
    enforce oslo.policy authorization. Any authenticated user who learns a
    Watcher audit webhook URL can POST to the webhook to trigger an
    administrator-owned EVENT audit and its associated action plan, regardless
    of the caller's project or role. The webhook endpoint has lacked policy
    enforcement since its introduction in the Ussuri release. Applied upstream
    patch: "Add policy enforcement to webhook trigger endpoint".
    (Closes: #1144880)
  * Add python3-ddt as build-depends, needed for this patch.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144880

#1144880#27
Date:
2026-08-19 21:06:43 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
watcher, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144880@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated watcher package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 12 Aug 2026 10:12:23 +0200
Source: watcher
Architecture: source
Version: 16.0.0-5
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1144880
Changes:
 watcher (16.0.0-5) unstable; urgency=high
 .
   * CVE-2026-XXXXX / OSSA-2026-036: Watcher webhook trigger endpoint does not
     enforce oslo.policy authorization. Any authenticated user who learns a
     Watcher audit webhook URL can POST to the webhook to trigger an
     administrator-owned EVENT audit and its associated action plan, regardless
     of the caller's project or role. The webhook endpoint has lacked policy
     enforcement since its introduction in the Ussuri release. Applied upstream
     patch: "Add policy enforcement to webhook trigger endpoint".
     (Closes: #1144880)
Checksums-Sha1:
 babfd42fa7d69d2e8e78b8d09a6b1ac5e634dbb3 3673 watcher_16.0.0-5.dsc
 d503a26e19df3172959805da4b698cb749722cff 13604 watcher_16.0.0-5.debian.tar.xz
 532cf284ac4a9383a4db997dd7acfac609fb9b07 18221 watcher_16.0.0-5_amd64.buildinfo
Checksums-Sha256:
 6f9ae7c7e1d8b7ba0d1245411f1baa9934516c5efdaea495a0c445224c8542c5 3673 watcher_16.0.0-5.dsc
 ebb90a6e83e0ded19ed088c2363cb701cbfb0d9c0b26eaa91d39bba877b83cbc 13604 watcher_16.0.0-5.debian.tar.xz
 d0111b8457523022d6857effb03656eeb8c8639133be5a3d4f273e3add726c0a 18221 watcher_16.0.0-5_amd64.buildinfo
Files:
 9a4450550f65f9600d7c4ffb390a4623 3673 net optional watcher_16.0.0-5.dsc
 a0eef9198409b05b8de8adefcf5d4ce9 13604 net optional watcher_16.0.0-5.debian.tar.xz
 4c4a6a09bb2750b3b592479f51e7f73d 18221 net optional watcher_16.0.0-5_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqGFTYACgkQ1BatFaxr
Q/6Yxw//aNw6kuFHNTUx1yePVdqjjPEegJv8WVJoFmjJqBJazrGRxOUN/ZySrwv3
FTWV8v/oJspaY/9z9EWnx4xXILLeJgY6luAx2HUTt7ZPG8HSi+51kceMrfU8WCTN
VtvW7VDC+mUmvTMupOY+2Rg5RWSSzDL6BoWQfEOfdmZCGsg8Nlr6hRCdvX3teF2W
2SShjU5Zgi9os1xTvJTOTKezLnXCnKI0Ixa6kF2DjQryKrZDcx8mwY7SSyhq3IZy
Siay+LoDbNGyPKhjziQBmpCAVylpvzgp672GTKxheYPUxwcVy9b8fX5P0UCy8/in
Uplqfptep5A8kyNO4zYiReEVCdgsCwo46sKUMSAp4MOrVmTzRIlVaajhFFTrRT4N
IzHKyURbb4zVZBhU+SmX6jCNpC0udqMUjGncRAyy/yWc8L0SUw7IJbkPsa10BTfb
aeu/nixrTgRbggcvCx5RUMuMWu/CRbTbYWmPmyBvaxqeu9If0rbnBnRZm6Rwn6B1
da2NJxJbkFzA9Z8A9Rq+KcNC2EOhc3uDI67xOtzbX9TMTYBgb/KWMXmqHVJZUg8a
wLYzKAQU26Fkbd3cvS2yl6h8NLhY0N89GYqbcJVEnecWoTObsvbQnb+HXyKrBnPu
rdvE42JiFS3RKn8wl6U8KBO9If9b+aWxE5SQgUmACKpw3q/B0Vk=
=Wh2/
-----END PGP SIGNATURE-----