PT-2026-95602 · Openstack+2 · Blazar
CVE-2026-93852
·
Published
2026-09-18
·
Updated
2026-09-18
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Blazar versions prior to 17.0.1
Description
The V2 lease listing operation at the 'GET /v2/leases' endpoint fails to enforce project scoping or administrator-only policies. This allows any authenticated user with access to the REST API to enumerate leases from other tenants, exposing sensitive data such as lease IDs, reservation IDs, resource IDs, and reservation metadata. Furthermore, the exposure of these lease IDs can be used to bypass object-level authorization, enabling an attacker to modify or delete the identified leases.
Recommendations
Update to version 17.0.1 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blazar