logo

Critical RCE Vulnerability Discovered in OpenStack Vitrage Root Cause Analysis Service

ID: 54ac75b0-dd75-50bf-9252-9d7eec519a5e

STIX ID: report--54ac75b0-dd75-50bf-9252-9d7eec519a5e

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-04

Date Updated: 2026-04-23

Author: Ddos

...
...

A security researcher disclosed a critical RCE vulnerability (CVE-2026-28370, CVSS 9.1) in OpenStack Vitrage's query parser (_create_query_function in vitrage/graph/query.py). An authenticated user of the Vitrage API can craft queries to achieve arbitrary code execution on the Vitrage host, risking full compromise of the RCA service; multiple Vitrage releases are affected and OpenStack has issued patches across supported branches with administrators urged to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.