Critical RCE Vulnerability Discovered in OpenStack Vitrage Root Cause Analysis Service
ID: 54ac75b0-dd75-50bf-9252-9d7eec519a5e
STIX ID: report--54ac75b0-dd75-50bf-9252-9d7eec519a5e
Feed Name: securityonline.info
A security researcher disclosed a critical RCE vulnerability (CVE-2026-28370, CVSS 9.1) in OpenStack Vitrage's query parser (_create_query_function in vitrage/graph/query.py). An authenticated user of the Vitrage API can craft queries to achieve arbitrary code execution on the Vitrage host, risking full compromise of the RCA service; multiple Vitrage releases are affected and OpenStack has issued patches across supported branches with administrators urged to update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
