Description
A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines.
Published: 2026-09-01
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect access control enforcement in OpenNebula allows an authenticated user with basic permissions to run commands on virtual machines owned by other users via the one.vm.exec function. This flaw results in a permission bypass that can compromise confidentiality, integrity, and availability on the target VM. The weakness is an authorization error, corresponding to CWE-284.

Affected Systems

OpenNebula Systems’ OpenNebula platform, all releases before 7.4, is affected. The issue applies to every deployment of the product that relies on the one.vm.exec API and runs the qemu‑agent on virtual machines.

Risk and Exploitability

The CVSS base score is 8.7, indicating high severity. EPSS data are not available, and the vulnerability is not listed in CISA’s KEV. An attacker only needs valid credentials with minimal rights, the VM identifier, and a machine with the qemu‑agent running. Once the one.vm.exec function is invoked, arbitrary commands are executed on the target VM, giving complete control over the compromised instance. Because the exploit requires authenticated access, the attack vector is internal or compromised user, but the impact is significant across the affected infrastructure.

Generated by OpenCVE AI on September 1, 2026 at 12:27 UTC.

Remediation

Vendor Solution

Update to OpenNebula version 7.4.


OpenCVE Recommended Actions

  • Upgrade to OpenNebula version 7.4 or later to obtain the access‑control fix.
  • Disable the qemu‑agent on virtual machines that do not require it, reducing the attack surface.
  • Restrict usage of the one.vm.exec API to authenticated users who have been granted explicit permissions for their own VMs, and review role definitions to ensure proper authorization control.

Generated by OpenCVE AI on September 1, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines.
Title Lack of authorisation in OpenNebula by OpenNebula Systems
First Time appeared Opennebula Systems
Opennebula Systems opennebula
Weaknesses CWE-284
CPEs cpe:2.3:a:opennebula_systems:opennebula:*:*:*:*:*:*:*:*
Vendors & Products Opennebula Systems
Opennebula Systems opennebula
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Opennebula Systems Opennebula
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-09-01T12:17:49.009Z

Reserved: 2026-09-01T08:05:51.571Z

Link: CVE-2026-84165

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T11:16:45.713

Modified: 2026-09-01T13:20:09.187

Link: CVE-2026-84165

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T12:30:04Z

Weaknesses