CVE-2026-46448
Awaiting Analysis
Awaiting Analysis - Queue
OpenStack Nova Server Create API Missing Placement Allocation
Publication date: 2026-06-16
Last updated on: 2026-06-16
Assigner: MITRE
Description
Description
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| openstack | nova | From 18.0.0 (inc) to 31.3.1 (exc) |
| openstack | nova | From 32.0.0 (inc) to 32.2.1 (exc) |
| openstack | nova | From 33.0.0 (inc) to 33.0.2 (exc) |
| openstack | nova | to 2024.1 (inc) |
| openstack | nova | to 33.0.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-669 | The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource. |