CVE-2026-76878 | OpenStack Aodh/Watcher up to 20.0.0/21.0.0/22.0.0 Alarm List API/Webhook Trigger Endpoint all_projects/project_id improper authorization

SecurityVulns

A vulnerability classified as very critical has been found in OpenStack Aodh and Watcher up to 20.0.0/21.0.0/22.0.0. This impacts an unknown function of the component Alarm List API/Webhook Trigger Endpoint. Performing a manipulation of the argument all_projects/project_id results in improper authorization.

This vulnerability is reported as CVE-2026-76878. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More