PT-2026-95602 · Openstack+2 · Blazar

CVE-2026-93852

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Blazar versions prior to 17.0.1
Description The V2 lease listing operation at the 'GET /v2/leases' endpoint fails to enforce project scoping or administrator-only policies. This allows any authenticated user with access to the REST API to enumerate leases from other tenants, exposing sensitive data such as lease IDs, reservation IDs, resource IDs, and reservation metadata. Furthermore, the exposure of these lease IDs can be used to bypass object-level authorization, enabling an attacker to modify or delete the identified leases.
Recommendations Update to version 17.0.1 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93852

Affected Products

Blazar