Impact
An incorrect access control enforcement in OpenNebula allows an authenticated user with basic permissions to run commands on virtual machines owned by other users via the one.vm.exec function. This flaw results in a permission bypass that can compromise confidentiality, integrity, and availability on the target VM. The weakness is an authorization error, corresponding to CWE-284.
Affected Systems
OpenNebula Systems’ OpenNebula platform, all releases before 7.4, is affected. The issue applies to every deployment of the product that relies on the one.vm.exec API and runs the qemu‑agent on virtual machines.
Risk and Exploitability
The CVSS base score is 8.7, indicating high severity. EPSS data are not available, and the vulnerability is not listed in CISA’s KEV. An attacker only needs valid credentials with minimal rights, the VM identifier, and a machine with the qemu‑agent running. Once the one.vm.exec function is invoked, arbitrary commands are executed on the target VM, giving complete control over the compromised instance. Because the exploit requires authenticated access, the attack vector is internal or compromised user, but the impact is significant across the affected infrastructure.
OpenCVE Enrichment