CVE-2026-74248
Publication date 14 August 2026
Last updated 24 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| octavia | 26.04 LTS resolute |
Fixed 1:18.0.0-0ubuntu2.1
|
| 24.04 LTS noble |
Fixed 1:14.0.0-0ubuntu1.6
|
|
| 22.04 LTS jammy |
Fixed 1:10.1.1-0ubuntu1.5
|
|
| 20.04 LTS focal |
Needs evaluation
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
4.3 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
References
Related Ubuntu Security Notices (USN)
- USN-8814-1
- Octavia vulnerabilities
- 24 September 2026