cve-2026-55748

MEDIUM CVSS 6.0 opencve
Description

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.

Timeline
Published
2026-06-17 15:17 UTC
Last Modified
2026-09-22
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 6.0 MEDIUM CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L mitre
3.1 6.0 MEDIUM CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L nvd
3.1 6.0 MEDIUM CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L opencve
3.1 6.0 MEDIUM CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L redhat
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "advisories": [
    {
      "id": "GHSA-6wrm-x65g-hr4p",
      "source": "ghsa",
      "title": "OpenStack Horizon RC file generation does not escape special characters in project names",
      "url": "https://github.com/advisories/GHSA-6wrm-x65g-hr4p"
    }
  ],
  "cve": "CVE-2026-55748",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[8.0.0,25.3.3)"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[25.4.0,25.5.3)"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[25.6.0,25.7.4)"
            }
          }
        ],
        "enrichment": {
          "confidence": 95.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 95.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "Horizon",
          "source": "cna",
          "vendor": "OpenStack"
        },
        "product": "horizon",
        "vendor": "openstack"
      }
    ],
    "created": "2026-06-18T20:45:03.338786+00:00",
    "updated": "2026-06-18T21:45:04.768019+00:00",
    "vendors": [
      "openstack",
      "openstack$PRODUCT$horizon"
    ]
  },
  "epss": {
    "score": 0.0046
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-06-17T14:12:20.715000+00:00",
    "description": "OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6,
        "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/55xxx/CVE-2026-55748.json",
    "references": [
      "https://launchpad.net/bugs/2152240",
      "https://wiki.openstack.org/wiki/OSSN/OSSN-0097"
    ],
    "title": null,
    "updated": "2026-06-17T15:40:12.791000+00:00",
    "vendors": [
      "openstack",
      "openstack$PRODUCT$horizon"
    ],
    "weaknesses": [
      "CWE-78"
    ]
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-06-17T15:17:02.503000+00:00",
    "description": "OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.0,
        "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-55748.json",
    "references": [
      "https://launchpad.net/bugs/2152240",
      "https://wiki.openstack.org/wiki/OSSN/OSSN-0097"
    ],
    "title": null,
    "updated": "2026-09-22T15:41:27.873000+00:00",
    "vendors": [
      "openstack",
      "openstack$PRODUCT$horizon"
    ],
    "weaknesses": [
      "CWE-78"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-06-18T04:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": [
              "openstack",
              "openstack$PRODUCT$horizon"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "CWE-78"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "openstack",
                "openstack$PRODUCT$horizon"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://launchpad.net/bugs/2152240",
                "https://wiki.openstack.org/wiki/OSSN/OSSN-0097"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 6,
                  "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "54eeaa40-a53f-4ce8-95e5-00b20098e5fb"
      },
      {
        "created": "2026-06-18T16:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "OpenStack Horizon: OpenStack Horizon: Information disclosure or integrity compromise via crafted project name with shell metacharacters",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "https://nvd.nist.gov/vuln/detail/CVE-2026-55748",
                "https://www.cve.org/CVERecord?id=CVE-2026-55748"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {},
              "removed": {},
              "updated": {
                "threat_severity": {
                  "new": "Moderate",
                  "old": null
                }
              }
            },
            "type": "metrics"
          }
        ],
        "id": "ce355d12-3719-41e8-8f57-d63363813f34"
      },
      {
        "created": "2026-06-19T12:30:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "763542db-d41b-4be4-9689-aa1bd9ab8847"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "created": {
      "data": "2026-06-17T14:12:20+00:00",
      "provider": "redhat"
    },
    "description": {
      "data": "OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 6,
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.0046
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": "Moderate",
        "provider": "redhat"
      }
    },
    "references": {
      "data": [
        "https://launchpad.net/bugs/2152240",
        "https://nvd.nist.gov/vuln/detail/CVE-2026-55748",
        "https://wiki.openstack.org/wiki/OSSN/OSSN-0097",
        "https://www.cve.org/CVERecord?id=CVE-2026-55748"
      ],
      "providers": [
        "mitre",
        "nvd",
        "redhat"
      ]
    },
    "title": {
      "data": "OpenStack Horizon: OpenStack Horizon: Information disclosure or integrity compromise via crafted project name with shell metacharacters",
      "provider": "redhat"
    },
    "updated": {
      "data": "2026-06-18T21:45:04.768019+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "openstack",
        "openstack$PRODUCT$horizon"
      ],
      "providers": [
        "mitre",
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-78"
      ],
      "providers": [
        "mitre",
        "nvd",
        "redhat"
      ]
    }
  },
  "redhat": {
    "cpes": [],
    "created": "2026-06-17T14:12:20+00:00",
    "description": "A flaw was found in OpenStack Horizon. This vulnerability allows a highly privileged remote attacker, with user interaction, to craft a project name containing shell metacharacters. When scripts for OpenStack RC file downloading are produced, these metacharacters may be processed, potentially leading to information disclosure or integrity compromise. This issue is considered by some as a security hardening opportunity rather than a direct vulnerability.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.0,
        "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"
      },
      "threat_severity": "Moderate"
    },
    "redhat_repo_path": "2026/CVE-2026-55748.json",
    "references": [
      "https://launchpad.net/bugs/2152240",
      "https://nvd.nist.gov/vuln/detail/CVE-2026-55748",
      "https://wiki.openstack.org/wiki/OSSN/OSSN-0097",
      "https://www.cve.org/CVERecord?id=CVE-2026-55748"
    ],
    "title": "OpenStack Horizon: OpenStack Horizon: Information disclosure or integrity compromise via crafted project name with shell metacharacters",
    "updated": "2026-06-17T14:12:20+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-78"
    ]
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-06-17T14:12:20.715000+00:00",
    "description": "OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-06-17T15:40:08.717000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/55xxx/CVE-2026-55748.json",
    "weaknesses": []
  }
}
Enrichment data
View JSON API Download JSON