Skip to content
VulniPulse
Advisory severityMedium6.3Red Hat Linux

Medium [CVE-2026-76878] aodh / python-watcher: cross-project alarm enumeration and webhook missing authorization

This medium-severity Red Hat Linux advisory covers CVE-2026-76878 affecting Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-76878 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false.

The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project.

A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms.

A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role.

The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0). A flaw was found in OpenStack Aodh and Watcher.

In Watcher, the webhook trigger endpoint does not enforce oslo.policy authorization, allowing any authenticated user who learns an audit webhook URL to trigger EVENT audits and associated action plans regardless of project or role. RHOSP 16.2 is affected.

Affected versions
  • < 22.0.1

Official advisory · high-confidence parse· fetched 15 days ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · high-confidence parse· fetched 15 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Restrict network access to the Aodh API (default port 8042) and the Watcher API (default port 9322) to trusted administrative networks. Review Keystone role assignments to minimize users with project_reader or higher that can reach the Aodh API. The Watcher webhook path cannot be isolated from the main REST API. Keep enable_webhooks_auth=True (the default). Do not create or use event-based audits.

Official advisory · high-confidence parse· fetched 15 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.