{"id":"UBUNTU-CVE-2026-76878","details":"In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0).","modified":"2026-09-02T16:27:47Z","published":"2026-08-19T22:17:00Z","upstream":["CVE-2026-76878"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-76878"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-76878"},{"type":"REPORT","url":"https://launchpad.net/bugs/2161276"},{"type":"REPORT","url":"https://launchpad.net/bugs/2161771"},{"type":"REPORT","url":"https://security.openstack.org/ossa/OSSA-2026-036.html"},{"type":"REPORT","url":"https://lists.openstack.org/archives/list/openstack-announce@lists.openstack.org/thread/O6PKAUNMNZP6FRHLUUGBYELCRBEPB52B/"},{"type":"REPORT","url":"https://www.openwall.com/lists/oss-security/2026/08/19/5"}],"affected":[{"package":{"name":"aodh","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/aodh?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.0-6","1.0.0-7","2.0.0~b1-0ubuntu1","2.0.0~b1-0ubuntu2","2.0.0~b2-2ubuntu1","2.0.0~b2-2ubuntu2","2.0.0~b3-0ubuntu1","2.0.0~rc1-0ubuntu1","2.0.0-0ubuntu1","2.0.1-0ubuntu1","2.0.2-0ubuntu1","2.0.4-0ubuntu1","2.0.5-0ubuntu1","2.0.6-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"aodh-api","binary_version":"2.0.6-0ubuntu1"},{"binary_version":"2.0.6-0ubuntu1","binary_name":"aodh-common"},{"binary_version":"2.0.6-0ubuntu1","binary_name":"aodh-evaluator"},{"binary_name":"aodh-expirer","binary_version":"2.0.6-0ubuntu1"},{"binary_version":"2.0.6-0ubuntu1","binary_name":"aodh-listener"},{"binary_name":"aodh-notifier","binary_version":"2.0.6-0ubuntu1"},{"binary_name":"python-aodh","binary_version":"2.0.6-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-76878.json"}},{"package":{"name":"aodh","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/aodh?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.0-0ubuntu2","6.0.0~b1~git20171213.3fcb2843-0ubuntu2","6.0.0~b1~git20180129.f9d322ea-0ubuntu1","6.0.0-0ubuntu1","6.0.1-0ubuntu1","6.0.1-0ubuntu1.1","6.0.1-0ubuntu1.2"],"ecosystem_specific":{"binaries":[{"binary_name":"aodh-api","binary_version":"6.0.1-0ubuntu1.2"},{"binary_name":"aodh-common","binary_version":"6.0.1-0ubuntu1.2"},{"binary_name":"aodh-evaluator","binary_version":"6.0.1-0ubuntu1.2"},{"binary_version":"6.0.1-0ubuntu1.2","binary_name":"aodh-expirer"},{"binary_name":"aodh-listener","binary_version":"6.0.1-0ubuntu1.2"},{"binary_name":"aodh-notifier","binary_version":"6.0.1-0ubuntu1.2"},{"binary_version":"6.0.1-0ubuntu1.2","binary_name":"python-aodh"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-76878.json"}},{"package":{"name":"watcher","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/watcher?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.4.1-0ubuntu1","1:1.5.0-0ubuntu1","1:1.6.0-0ubuntu1","1:1.7.0-0ubuntu1","1:1.7.0-0ubuntu2","1:1.8.0-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"python-watcher","binary_version":"1:1.8.0-0ubuntu1"},{"binary_version":"1:1.8.0-0ubuntu1","binary_name":"watcher-api"},{"binary_name":"watcher-applier","binary_version":"1:1.8.0-0ubuntu1"},{"binary_version":"1:1.8.0-0ubuntu1","binary_name":"watcher-common"},{"binary_name":"watcher-decision-engine","binary_version":"1:1.8.0-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-76878.json"}},{"package":{"name":"aodh","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/aodh?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.0.0-0ubuntu1","10.0.0~b1~git2019121610.b18d0bae-0ubuntu1","10.0.0~b2~git2020020508.83ef3a81-0ubuntu1","10.0.0~b3~git2020032411.ed802044-0ubuntu1","10.0.0~b3~git2020041012.6ae7f90a-0ubuntu1","10.0.0-0ubuntu0.20.04.1"],"ecosystem_specific":{"binaries":[{"binary_version":"10.0.0-0ubuntu0.20.04.1","binary_name":"aodh-api"},{"binary_name":"aodh-common","binary_version":"10.0.0-0ubuntu0.20.04.1"},{"binary_version":"10.0.0-0ubuntu0.20.04.1","binary_name":"aodh-evaluator"},{"binary_version":"10.0.0-0ubuntu0.20.04.1","binary_name":"aodh-expirer"},{"binary_version":"10.0.0-0ubuntu0.20.04.1","binary_name":"aodh-listener"},{"binary_name":"aodh-notifier","binary_version":"10.0.0-0ubuntu0.20.04.1"},{"binary_version":"10.0.0-0ubuntu0.20.04.1","binary_name":"python3-aodh"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-76878.json"}},{"package":{"name":"watcher","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/watcher?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:3.0.0-0ubuntu1","1:4.0.0~b2~git2020021315.2591b036-0ubuntu1","1:4.0.0~b3~git2020032633.c17e96d3-0ubuntu1","1:4.0.0~b3~git2020041014.f3c427bd-0ubuntu1","1:4.0.0-0ubuntu0.20.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-watcher","binary_version":"1:4.0.0-0ubuntu0.20.04.1"},{"binary_name":"watcher-api","binary_version":"1:4.0.0-0ubuntu0.20.04.1"},{"binary_version":"1:4.0.0-0ubuntu0.20.04.1","binary_name":"watcher-applier"},{"binary_version":"1:4.0.0-0ubuntu0.20.04.1","binary_name":"watcher-common"},{"binary_name":"watcher-decision-engine","binary_version":"1:4.0.0-0ubuntu0.20.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-76878.json"}},{"package":{"name":"aodh","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/aodh?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:13.0.0-0ubuntu1","1:13.0.0+git2022011215.8ac7c65c-0ubuntu1","1:14.0.0~rc1-0ubuntu1","1:14.0.0~rc1-0ubuntu2","1:14.0.0-0ubuntu1","1:14.0.0-0ubuntu1.1","1:14.1.0-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"1:14.1.0-0ubuntu1","binary_name":"aodh-api"},{"binary_name":"aodh-common","binary_version":"1:14.1.0-0ubuntu1"},{"binary_name":"aodh-evaluator","binary_version":"1:14.1.0-0ubuntu1"},{"binary_version":"1:14.1.0-0ubuntu1","binary_name":"aodh-expirer"},{"binary_name":"aodh-listener","binary_version":"1:14.1.0-0ubuntu1"},{"binary_version":"1:14.1.0-0ubuntu1","binary_name":"aodh-notifier"},{"binary_name":"python3-aodh","binary_version":"1:14.1.0-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-76878.json"}},{"package":{"name":"watcher","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/watcher?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:7.0.0-0ubuntu1","2:7.0.0+git2021120910.e4fab0ce-0ubuntu1","2:7.0.0+git2022011310.01d74d0a-0ubuntu1","2:8.0.0-0ubuntu1","2:8.0.0-0ubuntu1.1","2:8.0.0-0ubuntu1.2"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-watcher","binary_version":"2:8.0.0-0ubuntu1.2"},{"binary_name":"watcher-api","binary_version":"2:8.0.0-0ubuntu1.2"},{"binary_name":"watcher-applier","binary_version":"2:8.0.0-0ubuntu1.2"},{"binary_name":"watcher-common","binary_version":"2:8.0.0-0ubuntu1.2"},{"binary_name":"watcher-decision-engine","binary_version":"2:8.0.0-0ubuntu1.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-76878.json"}},{"package":{"name":"aodh","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/aodh?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:17.0.0-0ubuntu2","1:17.0.0+git2024011915.3d49da3c-0ubuntu1","1:17.0.0+git2024030809.64e0f7c8-0ubuntu1","1:18.0.0~rc1-0ubuntu1","1:18.0.0-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"aodh-api","binary_version":"1:18.0.0-0ubuntu1"},{"binary_name":"aodh-common","binary_version":"1:18.0.0-0ubuntu1"},{"binary_version":"1:18.0.0-0ubuntu1","binary_name":"aodh-evaluator"},{"binary_version":"1:18.0.0-0ubuntu1","binary_name":"aodh-expirer"},{"binary_name":"aodh-listener","binary_version":"1:18.0.0-0ubuntu1"},{"binary_name":"aodh-notifier","binary_version":"1:18.0.0-0ubuntu1"},{"binary_version":"1:18.0.0-0ubuntu1","binary_name":"python3-aodh"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-76878.json"}},{"package":{"name":"watcher","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/watcher?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:11.0.0-0ubuntu1","2:11.0.0+git2024020610.c95ce4ec-0ubuntu1","2:12.0.0~rc1-0ubuntu2","2:12.0.0-0ubuntu1","2:12.0.0-0ubuntu1.1","2:12.0.0-0ubuntu1.2","2:12.0.0-0ubuntu1.3"],"ecosystem_specific":{"binaries":[{"binary_version":"2:12.0.0-0ubuntu1.3","binary_name":"python3-watcher"},{"binary_version":"2:12.0.0-0ubuntu1.3","binary_name":"watcher-api"},{"binary_name":"watcher-applier","binary_version":"2:12.0.0-0ubuntu1.3"},{"binary_name":"watcher-common","binary_version":"2:12.0.0-0ubuntu1.3"},{"binary_version":"2:12.0.0-0ubuntu1.3","binary_name":"watcher-decision-engine"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-76878.json"}},{"package":{"name":"aodh","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/aodh?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:21.0.0-0ubuntu1","1:21.0.0-0ubuntu2","1:21.0.0+git20260218.38.d7e8427e-0ubuntu1","1:22.0.0~rc1-0ubuntu1","1:22.0.0-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"aodh-api","binary_version":"1:22.0.0-0ubuntu1"},{"binary_version":"1:22.0.0-0ubuntu1","binary_name":"aodh-common"},{"binary_name":"aodh-evaluator","binary_version":"1:22.0.0-0ubuntu1"},{"binary_name":"aodh-expirer","binary_version":"1:22.0.0-0ubuntu1"},{"binary_name":"aodh-listener","binary_version":"1:22.0.0-0ubuntu1"},{"binary_name":"aodh-notifier","binary_version":"1:22.0.0-0ubuntu1"},{"binary_version":"1:22.0.0-0ubuntu1","binary_name":"python3-aodh"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-76878.json"}},{"package":{"name":"watcher","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/watcher?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2:15.0.0-0ubuntu1","2:15.0.0+git20260121.89.f6aac33e-0ubuntu1","2:16.0.0~rc1-0ubuntu2","2:16.0.0-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"2:16.0.0-0ubuntu1","binary_name":"python3-watcher"},{"binary_name":"watcher-api","binary_version":"2:16.0.0-0ubuntu1"},{"binary_version":"2:16.0.0-0ubuntu1","binary_name":"watcher-applier"},{"binary_name":"watcher-common","binary_version":"2:16.0.0-0ubuntu1"},{"binary_name":"watcher-decision-engine","binary_version":"2:16.0.0-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-76878.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:H/SA:L"},{"type":"Ubuntu","score":"medium"}]}