A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines. | |
| Title | Lack of authorisation in OpenNebula by OpenNebula Systems | |
| First Time appeared |
Opennebula Systems
Opennebula Systems opennebula |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:opennebula_systems:opennebula:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opennebula Systems
Opennebula Systems opennebula |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2026-09-01T10:49:22.381Z
Updated: 2026-09-01T12:17:49.009Z
Reserved: 2026-09-01T08:05:51.571Z
Link: CVE-2026-84165
Updated: 2026-09-01T12:17:44.003Z
Status : Deferred
Published: 2026-09-01T11:16:45.713
Modified: 2026-09-01T20:50:58.753
Link: CVE-2026-84165
No data.