In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of the Vitrage service. All deployments exposing the Vitrage API are affected. This occurs in _create_query_function in vitrage/graph/query.py.
History

Fri, 27 Feb 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Openstack
Openstack vitrage
CPEs cpe:2.3:a:openstack:vitrage:*:*:*:*:*:*:*:*
Vendors & Products Openstack
Openstack vitrage

Fri, 27 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Feb 2026 05:15:00 +0000

Type Values Removed Values Added
Description In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of the Vitrage service. All deployments exposing the Vitrage API are affected. This occurs in _create_query_function in vitrage/graph/query.py.
Weaknesses CWE-95
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-02-27T15:47:53.604Z

Reserved: 2026-02-27T04:52:33.518Z

Link: CVE-2026-28370

cve-icon Vulnrichment

Updated: 2026-02-27T15:47:49.473Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-27T05:18:20.757

Modified: 2026-02-27T16:58:27.747

Link: CVE-2026-28370

cve-icon Redhat

No data.