Impact
The vulnerability arises because OpenStack Neutron’s subnetpool onboarding API does not verify that the caller owns the subnets being onboarded. An authenticated user can therefore specify a network whose subnets belong to another project. When the API is called, those subnets are moved into the attacker’s subnetpool without ownership checks, which changes the subnet‑pool identifier of the victim’s subnets. This mutation alters L3 routing and address‑scope behavior for the victim’s routers, potentially disrupting traffic, leaking data, or preventing the victim’s owners from controlling their own network configuration.
Affected Systems
The issue affects installations of OpenStack Neutron prior to release 28.0.2 that enable subnetpool onboarding and expose shared or globally shared networks. Administrators should assume that any deployment using the API before the 28.0.2 release is vulnerable, regardless of additional context such as RBAC policies.
Risk and Exploitability
The CVSS score of 7.1 indicates a high overall risk, and the vulnerability is not listed in the CISA KEV catalog nor is EPSS data available. Based on the description it is inferred that an attacker must be authenticated and have membership in a project that can view the target network. Once authenticated, the endpoint can be exploited without further privileges, making this a classic authorization‑bypass situation. The lack of ownership checks permits an authenticated user to effectively re‑scope another project’s subnets, which elevates the attacker’s control over the victim’s networking resources.
OpenCVE Enrichment
Debian DLA
Debian DSA