> USN-8870-1: OpenStack Aodh and Watcher vulnerability
[DATE: 05/10/2026 15:04]
[LANGUAGE: EN]
Chen YuXiang discovered that OpenStack Aodh did not correctly enforce
project scoping in its alarm list API and that the OpenStack Watcher
webhook trigger endpoint did not apply authorization. An attacker could
possibly use this issue to access sensitive alarm metadata or trigger
unauthorized action plans.