Tag
high
advisory
OpenStack Keystone LDAP Authentication Bypass Vulnerability (CVE-2026-40683)
2 rules 3 TTPs 1 CVEOpenStack Keystone before 28.0.1 is vulnerable to an authentication bypass due to improper handling of the user enabled attribute in the LDAP identity backend when the user_enabled_invert configuration option is False, leading to disabled users being treated as enabled.
Keystone
openstack
ldap
authentication-bypass
2r
3t
1c
high
advisory
choieastsea simple-openstack-mcp OS Command Injection Vulnerability (CVE-2026-7066)
3 rules 1 TTP 1 CVEThe choieastsea simple-openstack-mcp application is vulnerable to OS command injection via the exec_openstack function in server.py, allowing remote attackers to execute arbitrary commands.
simple-openstack-mcp
command-injection
vulnerability
openstack
3r
1t
1c