← Vulnerability feed

Vulnerability record · CVE-2013-6426 · published 14 December 2013

CVE-2013-6426: Openstack heat permissions and access controls vulnerability

Openstack · Heat

The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.

4.0 CVSS 2.0 Medium EPSS 1.0% · top 37.7% CWE-264 · Permissions and access controls
4.0CVSS 2.0 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.

AV:N/AC:L/Au:S/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-6426 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.5CVE-2017-2621Openstack heat sensitive information in log file vulnerabilityAn access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improp…EPSS 0.41%5.0CVE-2024-7319Openstack heat information exposure vulnerabilityAn incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon …EPSS 0.39%5.0CVE-2023-1625Openstack heat vulnerabilityAn information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reve…EPSS 0.72%4.3CVE-2016-9185Openstack heat information exposure vulnerabilityIn OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network conf…EPSS 1.5%4.0CVE-2013-6428Openstack heat permissions and access controls vulnerabilityThe ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass …EPSS 1.7%3.5CVE-2014-3801Openstack heat information exposure vulnerabilityOpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remot…EPSS 1.6%5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed6.6CVE-2015-1769Windows Mount Manager symlink mishandling allows local privilege escalationThe Windows Mount Manager mishandles symbolic links, allowing a crafted USB device to trigger arbitrary code execution. Because the flaw is in a core…KEVEPSS 4.1%analysed

Source: NIST National Vulnerability Database (record CVE-2013-6426), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.