openstack-swift: openstack-swift: S3API cross-tenant object read via Swift-native header injection
Published Aug 5, 2026
6.0
MEDIUMCVSS 4.0
EPSS 0.44%
Description
In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed PUT request targeting their own bucket, causing Swift to perform a server-side copy from another tenant's private object. The source object authorization is bypassed because the S3API middleware has already authorized the request against the destination. The attacker can read any object whose project_id, container name, and object name are known, regardless of the source object's ACLs or ownership. This requires the non-default s3_acl=true configuration.
Affected products
-
- Version 2.18.0StatusaffectedConstraints<2.35.4
- Version 2.36.0StatusaffectedConstraints<2.36.3
- Version 2.37.0StatusaffectedConstraints<2.37.3
- Version 2.38.0StatusaffectedConstraints-
- Version
No data.
No data.
Red Hat OpenStack Platform 13 (Queens)
rhosp13/openstack-swift-account
Fix deferred
Red Hat OpenStack Platform 13 (Queens)
rhosp13/openstack-swift-base
Fix deferred
Red Hat OpenStack Platform 13 (Queens)
rhosp13/openstack-swift-container
Fix deferred
Red Hat OpenStack Platform 13 (Queens)
rhosp13/openstack-swift-object
Fix deferred
Red Hat OpenStack Platform 13 (Queens)
rhosp13/openstack-swift-proxy-server
Fix deferred
Red Hat OpenStack Platform 16.2
openstack-swift
Fix deferred
Red Hat OpenStack Platform 16.2
rhosp-rhel8/openstack-swift-account
Fix deferred
Red Hat OpenStack Platform 16.2
rhosp-rhel8/openstack-swift-base
Fix deferred
Red Hat OpenStack Platform 16.2
rhosp-rhel8/openstack-swift-container
Fix deferred
Red Hat OpenStack Platform 16.2
rhosp-rhel8/openstack-swift-object
Fix deferred
Red Hat OpenStack Platform 16.2
rhosp-rhel8/openstack-swift-proxy-server
Fix deferred
Red Hat OpenStack Platform 17.1
openstack-swift
Fix deferred
Red Hat OpenStack Platform 17.1
rhosp-rhel9/openstack-swift-account
Fix deferred
Red Hat OpenStack Platform 17.1
rhosp-rhel9/openstack-swift-base
Fix deferred
Red Hat OpenStack Platform 17.1
rhosp-rhel9/openstack-swift-container
Fix deferred
Red Hat OpenStack Platform 17.1
rhosp-rhel9/openstack-swift-object
Fix deferred
Red Hat OpenStack Platform 17.1
rhosp-rhel9/openstack-swift-proxy-server
Fix deferred
Red Hat OpenStack Platform 18.0
openstack-swift
Fix deferred
Red Hat OpenStack Platform 18.0
rhoso/openstack-swift-account-rhel9
Fix deferred
Red Hat OpenStack Platform 18.0
rhoso/openstack-swift-base-rhel9
Fix deferred
Red Hat OpenStack Platform 18.0
rhoso/openstack-swift-container-rhel9
Fix deferred
Red Hat OpenStack Platform 18.0
rhoso/openstack-swift-object-rhel9
Fix deferred
Red Hat OpenStack Platform 18.0
rhoso/openstack-swift-proxy-server-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-account | Fix deferred | n/a |
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-base | Fix deferred | n/a |
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-container | Fix deferred | n/a |
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-object | Fix deferred | n/a |
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-proxy-server | Fix deferred | n/a |
| Red Hat OpenStack Platform 16.2 | openstack-swift | Fix deferred | n/a |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-account | Fix deferred | n/a |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-base | Fix deferred | n/a |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-container | Fix deferred | n/a |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-object | Fix deferred | n/a |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-proxy-server | Fix deferred | n/a |
| Red Hat OpenStack Platform 17.1 | openstack-swift | Fix deferred | n/a |
| Red Hat OpenStack Platform 17.1 | rhosp-rhel9/openstack-swift-account | Fix deferred | n/a |
| Red Hat OpenStack Platform 17.1 | rhosp-rhel9/openstack-swift-base | Fix deferred | n/a |
| Red Hat OpenStack Platform 17.1 | rhosp-rhel9/openstack-swift-container | Fix deferred | n/a |
| Red Hat OpenStack Platform 17.1 | rhosp-rhel9/openstack-swift-object | Fix deferred | n/a |
| Red Hat OpenStack Platform 17.1 | rhosp-rhel9/openstack-swift-proxy-server | Fix deferred | n/a |
| Red Hat OpenStack Platform 18.0 | openstack-swift | Fix deferred | n/a |
| Red Hat OpenStack Platform 18.0 | rhoso/openstack-swift-account-rhel9 | Fix deferred | n/a |
| Red Hat OpenStack Platform 18.0 | rhoso/openstack-swift-base-rhel9 | Fix deferred | n/a |
| Red Hat OpenStack Platform 18.0 | rhoso/openstack-swift-container-rhel9 | Fix deferred | n/a |
| Red Hat OpenStack Platform 18.0 | rhoso/openstack-swift-object-rhel9 | Fix deferred | n/a |
| Red Hat OpenStack Platform 18.0 | rhoso/openstack-swift-proxy-server-rhel9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat OpenStack Platform (RHOSP) and Red Hat OpenStack Services on OpenShift (RHOSO) ship openstack-swift. This vulnerability requires the non-default s3_acl=true configuration, which the upstream documentation explicitly warns is experimental ('DON'T USE THIS for production before enough testing'). In default RHOSO deployments, s3_acl is not set, defaulting to false. Swift's native Keystone authorization properly denies cross-tenant access in this configuration. Deployments using the default s3_acl=false configuration are not affected. Only deployments that have explicitly set s3_acl=true in the [filter:s3api] section of proxy-server.conf are vulnerable.
Red Hat mitigation
Ensure the s3_acl configuration option is set to false (the default) in the [filter:s3api] section of proxy-server.conf. This completely mitigates the vulnerability because Swift's native authorization (Keystone/tempauth) will properly deny cross-tenant access attempts. If s3_acl=true is required and cannot be changed, restrict S3 API access to trusted networks or remove the s3api filter from the proxy-server pipeline until the patch is applied.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
1 other source (MITRE) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 5, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.44% (0.00439) | 35.93th | v5 (v2026.06.15) |
| Aug 5, 2026 | 0.25% (0.00253) | 16.65th | v5 (v2026.06.15) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-71192 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2503678 Issue Tracking
- https://launchpad.net/bugs/2158733 issue-tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-71192
- https://openwall.com/lists/oss-security/2026/07/28/26 vendor-advisorymailing-list
- https://security.openstack.org/ossa/OSSA-2026-030.html vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2026-71192
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-71192 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2503678 | Issue Tracking | |
| https://launchpad.net/bugs/2158733 | issue-tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-71192 | ||
| https://openwall.com/lists/oss-security/2026/07/28/26 | vendor-advisorymailing-list | |
| https://security.openstack.org/ossa/OSSA-2026-030.html | vendor-advisory | |
| https://www.cve.org/CVERecord?id=CVE-2026-71192 |
Change history (0)
No recorded changes yet.