Your message dated Wed, 19 Aug 2026 21:06:43 +0000
with message-id <[email protected]>
and subject line Bug#1144880: fixed in watcher 16.0.0-5
has caused the Debian Bug report #1144880,
regarding OSSA-2026-036: Watcher webhook authorization bypass
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1144880: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144880
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: watcher
Version: 14.0.0-1+deb13u1
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>
As per upstream announce at:
https://security.openstack.org/ossa/OSSA-2026-036.html
Date:
August 19, 2026
CVE:
CVE-2026-pending
Affects:
Aodh: >=10.0.0 <20.0.1, ==21.0.0, ==22.0.0
Watcher: >=4.0.0 <14.1.2, >=15.0.0 <15.1.2, >=16.0.0 <16.0.2
Description:
Chen YuXiang of the Institute of Computing Technology, Chinese Academy of
Sciences reported that OpenStack Aodh does not enforce project scope on the
alarm listing API when the all_projects query parameter is supplied with a
false value. A non-admin user holding only the reader role can list alarms
belonging to other projects, optionally targeting a specific project, exposing
alarm metadata such as webhook action URLs, signal endpoints, and project
identifiers. All Aodh deployments are affected.
The same reporter found that OpenStack Watcher does not apply authorization to
its webhook trigger endpoint. Any authenticated user who learns an audit’s
webhook URL, for example from the Aodh alarm metadata leaked above, can start
an EVENT audit and its associated action plan regardless of their own project
or role. All Watcher deployments are affected.
Patches:
https://review.opendev.org/1001503 (2025.1/epoxy (aodh))
https://review.opendev.org/1001509 (2025.1/epoxy (watcher))
https://review.opendev.org/1001502 (2025.2/flamingo (aodh))
https://review.opendev.org/1001508 (2025.2/flamingo (watcher))
https://review.opendev.org/1001501 (2026.1/gazpacho (aodh))
https://review.opendev.org/1001507 (2026.1/gazpacho (watcher))
https://review.opendev.org/1001500 (2026.2/hibiscus (development) (aodh))
https://review.opendev.org/1001505 (2026.2/hibiscus (development) (watcher))
Credits:
Chen YuXiang from Institute of Computing Technology, Chinese Academy of
Sciences
References:
https://launchpad.net/bugs/2161276
https://launchpad.net/bugs/2161771
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending
Notes:
A CVE identifier was requested from MITRE for the aodh vulnerability on
2026-08-03. The CVE will be added to this advisory by errata once assigned.
--- End Message ---
--- Begin Message ---
Source: watcher
Source-Version: 16.0.0-5
Done: Thomas Goirand <[email protected]>
We believe that the bug you reported is fixed in the latest version of
watcher, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated watcher package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 12 Aug 2026 10:12:23 +0200
Source: watcher
Architecture: source
Version: 16.0.0-5
Distribution: unstable
Urgency: high
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1144880
Changes:
watcher (16.0.0-5) unstable; urgency=high
.
* CVE-2026-XXXXX / OSSA-2026-036: Watcher webhook trigger endpoint does not
enforce oslo.policy authorization. Any authenticated user who learns a
Watcher audit webhook URL can POST to the webhook to trigger an
administrator-owned EVENT audit and its associated action plan, regardless
of the caller's project or role. The webhook endpoint has lacked policy
enforcement since its introduction in the Ussuri release. Applied upstream
patch: "Add policy enforcement to webhook trigger endpoint".
(Closes: #1144880)
Checksums-Sha1:
babfd42fa7d69d2e8e78b8d09a6b1ac5e634dbb3 3673 watcher_16.0.0-5.dsc
d503a26e19df3172959805da4b698cb749722cff 13604 watcher_16.0.0-5.debian.tar.xz
532cf284ac4a9383a4db997dd7acfac609fb9b07 18221 watcher_16.0.0-5_amd64.buildinfo
Checksums-Sha256:
6f9ae7c7e1d8b7ba0d1245411f1baa9934516c5efdaea495a0c445224c8542c5 3673
watcher_16.0.0-5.dsc
ebb90a6e83e0ded19ed088c2363cb701cbfb0d9c0b26eaa91d39bba877b83cbc 13604
watcher_16.0.0-5.debian.tar.xz
d0111b8457523022d6857effb03656eeb8c8639133be5a3d4f273e3add726c0a 18221
watcher_16.0.0-5_amd64.buildinfo
Files:
9a4450550f65f9600d7c4ffb390a4623 3673 net optional watcher_16.0.0-5.dsc
a0eef9198409b05b8de8adefcf5d4ce9 13604 net optional
watcher_16.0.0-5.debian.tar.xz
4c4a6a09bb2750b3b592479f51e7f73d 18221 net optional
watcher_16.0.0-5_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqGFTYACgkQ1BatFaxr
Q/6Yxw//aNw6kuFHNTUx1yePVdqjjPEegJv8WVJoFmjJqBJazrGRxOUN/ZySrwv3
FTWV8v/oJspaY/9z9EWnx4xXILLeJgY6luAx2HUTt7ZPG8HSi+51kceMrfU8WCTN
VtvW7VDC+mUmvTMupOY+2Rg5RWSSzDL6BoWQfEOfdmZCGsg8Nlr6hRCdvX3teF2W
2SShjU5Zgi9os1xTvJTOTKezLnXCnKI0Ixa6kF2DjQryKrZDcx8mwY7SSyhq3IZy
Siay+LoDbNGyPKhjziQBmpCAVylpvzgp672GTKxheYPUxwcVy9b8fX5P0UCy8/in
Uplqfptep5A8kyNO4zYiReEVCdgsCwo46sKUMSAp4MOrVmTzRIlVaajhFFTrRT4N
IzHKyURbb4zVZBhU+SmX6jCNpC0udqMUjGncRAyy/yWc8L0SUw7IJbkPsa10BTfb
aeu/nixrTgRbggcvCx5RUMuMWu/CRbTbYWmPmyBvaxqeu9If0rbnBnRZm6Rwn6B1
da2NJxJbkFzA9Z8A9Rq+KcNC2EOhc3uDI67xOtzbX9TMTYBgb/KWMXmqHVJZUg8a
wLYzKAQU26Fkbd3cvS2yl6h8NLhY0N89GYqbcJVEnecWoTObsvbQnb+HXyKrBnPu
rdvE42JiFS3RKn8wl6U8KBO9If9b+aWxE5SQgUmACKpw3q/B0Vk=
=Wh2/
-----END PGP SIGNATURE-----
pgpfAuDYb68E9.pgp
Description: PGP signature
--- End Message ---