PT-2026-95603 · Openstack · Openstack Blazar

CVE-2026-93854

·

Published

2026-09-18

·

Updated

2026-09-27

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OpenStack Blazar versions prior to 17.0.1
Description The V2 lease API fails to enforce object-level authorization during update and delete operations. This occurs because the authorize() wrapper searches for the lease using the keyword lease id, while the controller methods use the parameter id. Consequently, the lookup returns no result, causing the system to validate authorization based on the requesting user's own project id or user id rather than the actual owner of the lease. An authenticated user with knowledge of a lease ID can modify or delete leases belonging to other users and projects via the endpoints 'PUT /v2/leases/{lease id}' and 'DELETE /v2/leases/{lease id}'.
Recommendations Update to version 17.0.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93854

Affected Products

Openstack Blazar