USN-8870-1: authorisation flaw in OpenStack Aodh and Watcher on Ubuntu
Ubuntu fixes CVE-2026-76878: missing project scoping in Aodh and missing authorisation in the Watcher webhook. Update and restart the services.
UptimeMag editorial team · 5 October 2026 · 2 min read

Ubuntu has published the security notice USN-8870-1, fixing a vulnerability in OpenStack Aodh and OpenStack Watcher, the components responsible respectively for alarming (part of Ceilometer) and cloud optimisation in the OpenStack stack. This concerns anyone managing OpenStack deployments on Ubuntu 26.04 LTS, 24.04 LTS, 22.04 LTS and 20.04 LTS, as it exposes alarm metadata and allows unauthorised actions to be triggered.\n\n## The issue\n\nAccording to the official Ubuntu advisory, researcher Chen YuXiang discovered that Aodh did not correctly enforce project scoping in its alarm listing API, and that Watcher's webhook trigger endpoint applied no authorisation at all. The result, as Ubuntu states: "An attacker could possibly use this issue to access sensitive alarm metadata or trigger unauthorized action plans." The flaw is tracked as CVE-2026-76878.\n\n## Fixed packages and versions\n\n| Release | Package | Fixed version | Note |\n|---|---|---|---|\n| 26.04 LTS | python3-aodh | 1:22.0.0-0ubuntu1.1 | — |\n| 26.04 LTS | python3-watcher | 2:16.0.0-0ubuntu1+esm1 | requires Ubuntu Pro (ESM Apps) |\n| 24.04 LTS | python3-aodh | 1:18.0.0-0ubuntu1.1 | — |\n| 24.04 LTS | python3-watcher | 2:12.0.0-0ubuntu1.3+esm1 | requires Ubuntu Pro (ESM Apps) |\n| 22.04 LTS | python3-aodh | 1:14.1.0-0ubuntu1.1 | — |\n| 22.04 LTS | python3-watcher | 2:8.0.0-0ubuntu1.2+esm1 | requires Ubuntu Pro (ESM Apps) |\n| 20.04 LTS | python3-aodh | 10.0.0-0ubuntu0.20.04.1+esm1 | requires Ubuntu Pro |\n| 20.04 LTS | python3-watcher | 1:4.0.0-0ubuntu0.20.04.1+esm1 | requires Ubuntu Pro (ESM Apps) |\n\nFor several release and package combinations, the fix is only available with Ubuntu Pro via ESM Apps; Ubuntu notes that "a community fix might become publicly available in the future". Ubuntu Pro covers up to 25,000 packages in Main and Universe with ten years of security coverage, and is free for up to five machines.\n\n## What to do\n\nAfter the standard system update, both the aodh service and the watcher service must be restarted to apply the changes. Without a restart, the processes will continue running with the vulnerable code even though the packages have been updated.\n\nSource: official Ubuntu Security Notices advisory, USN-8870-1, published on 5 October 2026.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.