A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines.
History

Wed, 02 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines.
Title Lack of authorisation in OpenNebula by OpenNebula Systems
First Time appeared Opennebula Systems
Opennebula Systems opennebula
Weaknesses CWE-284
CPEs cpe:2.3:a:opennebula_systems:opennebula:*:*:*:*:*:*:*:*
Vendors & Products Opennebula Systems
Opennebula Systems opennebula
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2026-09-01T10:49:22.381Z

Updated: 2026-09-01T12:17:49.009Z

Reserved: 2026-09-01T08:05:51.571Z

Link: CVE-2026-84165

cve-icon Vulnrichment

Updated: 2026-09-01T12:17:44.003Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T11:16:45.713

Modified: 2026-09-01T20:50:58.753

Link: CVE-2026-84165

cve-icon Redhat

No data.