CVE-2026-74248: Openstack Octavia
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.
Affected products
- Openstack Octavia: before 16.0.2 (fixed in 16.0.2); version 17.0.0 only; version 18.0.0 only
Published 2026-08-14. Last modified 2026-09-09.