Lack of authorisation in OpenNebula by OpenNebula Systems

Posted date 01/09/2026
Identificador
INCIBE-2026-596
Importance
4 - High
Affected Resources

OpenNebula 7.4.

Description

INCIBE has coordinated the publication of a high-severity vulnerability affecting OpenNebula by OpenNebula Systems, a platform for managing virtualised data. The vulnerability was discovered by Yonghwa Lee, Xint from Theori.

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:

  • CVE-2026-84165: CVSS v4.0: 8.7 | CVSS /AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-284
Solution

Update to OpenNebula version 7.4.

Detail

CVE-2026-84165: a vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines.

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-84165 Alta No OpenNebula