CVE-2026-43002
CVE-2026-43002 is a medium-severity vulnerability in Openstack Horizon with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-696.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- EPSS exploit prediction: 1% (47th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-27406
- Weakness: CWE-696
- Affected product: Openstack Horizon
- Published:
- Last modified:
Description
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
Frequently asked questions
- What is CVE-2026-43002?
- An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
- How severe is CVE-2026-43002?
- CVE-2026-43002 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability low.
- Is CVE-2026-43002 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (47th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-43002?
- CVE-2026-43002 affects Openstack Horizon. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-43002?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-43002 have an EU (EUVD) identifier?
- Yes. CVE-2026-43002 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-27406.
- When was CVE-2026-43002 published?
- CVE-2026-43002 was published on 2026-05-05 and last updated on 2026-09-10.
References
- https://bugs.launchpad.net/horizon/+bug/2150331
- https://security.openstack.org/ossa/OSSA-2026-009.html
- https://www.openwall.com/lists/oss-security/2026/05/05/7
Affected products (1)
- cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:*
More vulnerabilities in Openstack Horizon
- CVE-2012-2144 — Medium (CVSS 6.8): Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack…
- CVE-2022-45582 — Medium (CVSS 6.1): Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.
- CVE-2020-29565 — Medium (CVSS 6.1): An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x,…
- CVE-2026-55748 — Medium (CVSS 6.0): OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name…
- CVE-2012-3540 — Medium (CVSS 5.8): Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote…
- CVE-2012-5476 — Medium (CVSS 5.5): Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world…
All CVEs affecting Openstack Horizon →
Other CWE-696 vulnerabilities
- CVE-2026-44108 — Critical (CVSS 9.8): Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system…
- CVE-2026-14169 — High (CVSS 8.1): Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted…
- CVE-2026-45033 — High (CVSS 7.8): GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security…
- CVE-2025-31485 — High (CVSS 7.5): API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL…
- CVE-2021-22569 — High (CVSS 7.5): An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that…
- CVE-2021-31379 — High (CVSS 7.5): An Incorrect Behavior Order vulnerability in the MAP-E automatic tunneling mechanism of Juniper Networks Junos OS…