PT-2026-95603 · Openstack · Openstack Blazar
CVE-2026-93854
·
Published
2026-09-18
·
Updated
2026-09-27
CVSS v4.0
7.2
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OpenStack Blazar versions prior to 17.0.1
Description
The V2 lease API fails to enforce object-level authorization during update and delete operations. This occurs because the
authorize() wrapper searches for the lease using the keyword lease id, while the controller methods use the parameter id. Consequently, the lookup returns no result, causing the system to validate authorization based on the requesting user's own project id or user id rather than the actual owner of the lease. An authenticated user with knowledge of a lease ID can modify or delete leases belonging to other users and projects via the endpoints 'PUT /v2/leases/{lease id}' and 'DELETE /v2/leases/{lease id}'.Recommendations
Update to version 17.0.1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Blazar