Home / mailings [USN-8870-1] OpenStack Aodh and Watcher vulnerability
Posted on 05 October 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8870-1
October 05, 2026
aodh, watcher vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
OpenStack Aodh and Watcher could allow unintended access to network
services.
Software Description:
- aodh: OpenStack Telemetry (Ceilometer) Alarming
- watcher: OpenStack Cloud Optimization as a Service
Details:
Chen YuXiang discovered that OpenStack Aodh did not correctly enforce
project scoping in its alarm list API and that the OpenStack Watcher
webhook trigger endpoint did not apply authorization. An attacker could
possibly use this issue to access sensitive alarm metadata or trigger
unauthorized action plans.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
python3-aodh 1:22.0.0-0ubuntu1.1
python3-watcher 2:16.0.0-0ubuntu1+esm1
Available with Ubuntu Pro
Ubuntu 24.04 LTS
python3-aodh 1:18.0.0-0ubuntu1.1
python3-watcher 2:12.0.0-0ubuntu1.3+esm1
Available with Ubuntu Pro
Ubuntu 22.04 LTS
python3-aodh 1:14.1.0-0ubuntu1.1
python3-watcher 2:8.0.0-0ubuntu1.2+esm1
Available with Ubuntu Pro
Ubuntu 20.04 LTS
python3-aodh 10.0.0-0ubuntu0.20.04.1+esm1
Available with Ubuntu Pro
python3-watcher 1:4.0.0-0ubuntu0.20.04.1+esm1
Available with Ubuntu Pro
After a standard system update you need to restart aodh and watcher to make
all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8870-1
CVE-2026-76878
--===============0288192631227852642==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
