{"id":"PYSEC-2026-878","summary":"OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests","details":"The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) add_rules, (2) remove_rules, (3) destroy, and other unspecified methods in compute/api.py when using non-default policies, which allows remote authenticated users to gain privileges via these API requests.","aliases":["CVE-2014-0167","GHSA-p258-xmh3-72pv"],"modified":"2026-07-07T11:45:28.194768125Z","published":"2026-07-06T08:03:25.931683Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0167"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2014:1084"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2014-0167"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1084868"},{"type":"WEB","url":"https://launchpad.net/bugs/1290537"},{"type":"PACKAGE","url":"https://opendev.org/openstack/nova"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/04/09/26"},{"type":"WEB","url":"http://www.ubuntu.com/usn/USN-2247-1"},{"type":"PACKAGE","url":"https://pypi.org/project/nova"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-p258-xmh3-72pv"}],"affected":[{"package":{"name":"nova","ecosystem":"PyPI","purl":"pkg:pypi/nova"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2013.1.0"},{"fixed":"2013.2.4"}]}],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/nova/PYSEC-2026-878.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U"}]}