Cyborg
This hub aggregates every CVE we track for Cyborg, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
2
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
HIGH1MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
0
0
0
0
2024-102026-09
Latest CVEs
The 2 most recently published vulnerabilities affecting Cyborg.
- CVE-2026-40213OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardle...7.4
- CVE-2026-40214In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), ...6.3
Product normalization is registry-driven with AI assist and human review. How it works