CVE-2026-49299: Openstack Neutron

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to create and update tags on same-project resources. Deployments running Neutron 26.0.0 or later are affected.

Affected products

  • Openstack Neutron: from 26.0.0, before 26.0.4 (fixed in 26.0.4); from 27.0.0, before 27.0.3 (fixed in 27.0.3); from 28.0.0, before 28.0.1 (fixed in 28.0.1)

Published 2026-05-28. Last modified 2026-07-21.