CVE-2026-55748: Openstack Horizon
Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.
Affected products
- Openstack Horizon: from 8.0.0, before 25.3.3 (fixed in 25.3.3); from 25.4.0, before 25.5.3 (fixed in 25.5.3); from 25.6.0, before 25.7.4 (fixed in 25.7.4)
Published 2026-06-17. Last modified 2026-09-22.