A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines.

Project Subscriptions

Vendors Products
Opennebula Systems Subscribe
Opennebula Subscribe
Advisories

No advisories yet.

Fixes

Solution

Update to OpenNebula version 7.4.


Workaround

No workaround given by the vendor.

History

Tue, 01 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the `one.vm.exec` function, without proper verification of access permissions. To exploit the vulnerability, it is only necessary to know the virtual machine’s identifier and for qemu-agent to be enabled on that machine. Exploitation could allow commands to be executed and compromise the confidentiality, integrity and availability of the affected virtual machines.
Title Lack of authorisation in OpenNebula by OpenNebula Systems
First Time appeared Opennebula Systems
Opennebula Systems opennebula
Weaknesses CWE-284
CPEs cpe:2.3:a:opennebula_systems:opennebula:*:*:*:*:*:*:*:*
Vendors & Products Opennebula Systems
Opennebula Systems opennebula
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-09-01T12:17:49.009Z

Reserved: 2026-09-01T08:05:51.571Z

Link: CVE-2026-84165

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T11:16:45.713

Modified: 2026-09-01T13:20:09.187

Link: CVE-2026-84165

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T12:30:04Z

Weaknesses