CVE-2026-55748
published 2026-06-17CVE-2026-55748: OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some…
medium6CVSS 3.1
AVNACHPRHUIRSUCHIHAL
EPSS
0.19%
8.9th percentile
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | horizon | >= 25.4.0 < 25.5.3 | 25.5.3 |
| openstack | horizon | >= 25.6.0 < 25.7.4 | 25.7.4 |
| openstack | horizon | >= 8.0.0 < 25.3.3 | 25.3.3 |
| rhoso | openstack-horizon-rhel9 | — | — |
| rhosp-rhel8 | openstack-horizon | — | — |
| rhosp-rhel9 | openstack-horizon | — | — |
| rhosp13 | openstack-horizon | — | — |
CVSS provenance
cvelistv5v3.16.0MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Horizon RC file generation does not escape special characters in project names
ghsa·2026-06-17
CVE-2026-55748 [MEDIUM] CWE-78 OpenStack Horizon RC file generation does not escape special characters in project names
OpenStack Horizon RC file generation does not escape special characters in project names
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.
VulDB
OpenStack Horizon up to 25.3.2/25.5.2/25.7.3 RC File os command injection
vuldb·2026-06-17
CVE-2026-55748 [CRITICAL] OpenStack Horizon up to 25.3.2/25.5.2/25.7.3 RC File os command injection
A vulnerability was found in OpenStack Horizon up to 25.3.2/25.5.2/25.7.3. It has been rated as critical. Affected by this issue is some unknown functionality of the component RC File Handler. This manipulation causes os command injection.
This vulnerability appears as CVE-2026-55748. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
CVEList
CVE-2026-55748: OpenStack Horizon before 25
cvelistv5·2026-06-17·CVSS 6.0
CVE-2026-55748 [MEDIUM] CWE-78 CVE-2026-55748: OpenStack Horizon before 25
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.
Red Hat
OpenStack Horizon: OpenStack Horizon: Information disclosure or integrity compromise via crafted project name with shell metacharacters
vendor_redhat·2026-06-17·CVSS 6.0
CVE-2026-55748 [MEDIUM] CWE-78 OpenStack Horizon: OpenStack Horizon: Information disclosure or integrity compromise via crafted project name with shell metacharacters
OpenStack Horizon: OpenStack Horizon: Information disclosure or integrity compromise via crafted project name with shell metacharacters
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.
A flaw was found in OpenStack Horizon. This vulnerability allows a highly privileged remote attacker, with user interaction, to craft a project name containing shell metacharacters. When scripts for OpenStack RC file downloading are produced, these metacharacters may be processed, potentially leading to information disclosure or integrity compromise. This issue is considered by some as
No detection rules found.
No public exploits indexed.
2026-06-17
Published