CVE-2026-43002
published 2026-05-05CVE-2026-43002: An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.36%
29.4th percentile
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
ghsa5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vxvf-xvm3-p8j5: An issue was discovered in OpenStack Horizon 25
ghsa_unreviewed·2026-05-05·CVSS 5.0
CVE-2026-43002 [MEDIUM] CWE-696 GHSA-vxvf-xvm3-p8j5: An issue was discovered in OpenStack Horizon 25
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
VulDB
OpenStack Horizon up to 25.7.2 incorrect behavior order (EUVD-2026-27406)
vuldb·2026-05-05·CVSS 5.3
CVE-2026-43002 [MEDIUM] OpenStack Horizon up to 25.7.2 incorrect behavior order (EUVD-2026-27406)
A vulnerability, which was classified as problematic, was found in OpenStack Horizon up to 25.7.2. The affected element is an unknown function. Such manipulation leads to incorrect behavior order.
This vulnerability is uniquely identified as CVE-2026-43002. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
GHSA
OpenStack Horizon has Incorrect Behavior Order
ghsa·2026-05-05·CVSS 5.0
CVE-2026-43002 [MEDIUM] CWE-696 OpenStack Horizon has Incorrect Behavior Order
OpenStack Horizon has Incorrect Behavior Order
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-05
Published