Executive brief
OpenStack Neutron, the networking component for OpenStack cloud environments, contains a flaw in how it manages permissions for shared networks. A project manager could exploit this to gain unauthorized 'trusted' status for their network connections on a shared network they do not own. This could allow them to impersonate other users or bypass security protections, potentially leading to data interception or disruption of service for other tenants on the same network.
Technical details
An authorization bypass vulnerability exists in OpenStack Neutron's Role-Based Access Control (RBAC) policies. The default policy incorrectly allowed users with the PROJECT_MANAGER role to set the 'device_owner' attribute to 'network:*' values (e.g., 'network:dhcp') on shared networks, even if they did not own the network. Because 'network:' prefixed ports are treated as trusted system services, they often bypass security group rules and anti-spoofing protections (DHCP, MAC, and IP spoofing). This is a regression of a previous security fix. The issue is resolved in Neutron version 28.0.1 by requiring network ownership for project managers to set these trusted device owner values.
Affected products
- OpenStack Neutron < 28.0.1
Timeline
- 2026-05-10: other: Bug reported to Launchpad
- 2026-06-04: disclosed: Public disclosure and advisory published
- 2026-06-04: advisory
- 2026-07-15: other: Advisory updated