External risk intelligence

OpenStack Zaqar WSGI Authentication Bypass Leading to Project Data Compromise.

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-97404

OpenStack Zaqar is a messaging service designed to be accessed via API. As a messaging queuing service, it is commonly deployed as an internet-facing or network-accessible API endpoint for distributed applications, making it a likely target for remote network interaction.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in OpenStack Zaqar's WSGI transport that could allow unauthenticated attackers to bypass authentication and access project resources. If administrative roles are claimed, these attackers could also perform administrative actions. The vulnerability is present in deployments using the WSGI transport with authentication.

  • Unauthenticated access to project queues and messages.
  • Affects systems using WSGI transport with authentication.
  • Confirm relevance and exposure to Zaqar WSGI deployments.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authentication and pre-signed URL verification by sending a request with an empty URL-Signature header to the WSGI transport of OpenStack Zaqar. This allows them to manipulate queues, messages, claims, and subscriptions within a known project, and potentially perform administrative actions if they can also claim an administrative role.

  • Requires network access and knowledge of a project's UUID.
  • Triggers when an empty URL-Signature header is sent.
  • Risk includes unauthorized data access and administrative control.

Live Threat

Current exploitation, exposure, and threat context

In OpenStack Zaqar deployments using the WSGI transport with authentication, an unauthenticated attacker could bypass security controls to access project-specific queues, messages, claims, and subscriptions. This could potentially extend to administrative operations in certain configurations.

  • Project data and queues at risk.
  • Bypasses authentication via crafted header.
  • Allows unauthorized data access and modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

For deployments utilizing OpenStack Zaqar with the WSGI transport, the platform or infrastructure teams are typically responsible for its management and security. The first practical step is to identify all instances of Zaqar using WSGI transport, confirm their reachability and business criticality, and then identify the accountable project owner to plan remediation based on the assessed risk.

  • Platform/Infrastructure teams own the issue.
  • Verify WSGI transport and project UUID knowledge.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is OpenStack Zaqar?

OpenStack Zaqar is a multi-tenant messaging and notification service designed for distributed applications. It provides a platform for developers to exchange messages between different components of their cloud infrastructure, acting as a message queuing service that typically exposes API endpoints for clients to interact with queues, subscriptions, and claims.

How does CVE-2026-97404 cause an authentication bypass?

This vulnerability, classified as CWE-348 (Use of Less Trusted Source), occurs because the WSGI transport in Zaqar fails to properly validate the URL-Signature header. By supplying an empty header, the service inadvertently skips necessary security checks. This allows an attacker to bypass Keystone authentication and pre-signed URL requirements entirely, effectively masquerading as a legitimate user.

Do I need specific access to trigger this Zaqar vulnerability?

Yes. An attacker must have network reachability to the Zaqar API and possess the specific UUID of a target project. The flaw is triggered specifically by sending a request with an empty URL-Signature header. Importantly, deployments using the websocket transport are not affected by this specific issue, as the flaw is isolated to the WSGI transport configuration.

Is my system at risk for this CVE-2026-97404?

Halo Surface Signal indicates that because Zaqar is designed to function as an API, it is frequently deployed with network-accessible endpoints. If your Zaqar service is configured with the WSGI transport and enabled authentication, it is exposed to this risk. Systems that are internet-facing are at a higher likelihood of being targeted by remote actors compared to those strictly restricted to internal networks.

What should I do first to address this security concern?

Start by auditing your infrastructure to pinpoint all instances of OpenStack Zaqar currently utilizing the WSGI transport. Once identified, evaluate the reachability and criticality of these instances. Coordinate with your project owners to prioritize these services for updates or security hardening, ensuring that the platform configuration is aligned with the latest security standards provided by the OpenStack maintainers.

References