CVE-2026-40212: Openstack Skyline

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs.

Affected products

  • Openstack Skyline: before 5.0.1 (fixed in 5.0.1); version 6.0.0 only; version 7.0.0 only

Published 2026-04-10. Last modified 2026-06-17.