OCTOBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-93852

HIGH · CVSS 7.1 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-11

CyberRota Analysis

AI-Generated

OpenStack Blazar versions prior to 17.0.1 are vulnerable due to improper project scoping in the V2 lease listing operation, allowing any authenticated user to access lease information across all projects. This exposure can lead to unauthorized enumeration of lease details, including IDs and metadata, and potentially enable attackers to modify or delete leases. Organizations using affected versions of OpenStack Blazar should prioritize patching to mitigate the risk of data exposure and unauthorized actions within their environments.

CVE
CVE-2026-93852
Severity
HIGH
CVSS
7.1
EPSS
0.37%

Original NVD Description

In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the Blazar REST API can enumerate leases belonging to other tenants, exposing lease IDs, reservation IDs, resource IDs, and reservation metadata. The exposed lease IDs also enable the object-level authorization bypass tracked in the companion request, allowing an attacker to then modify or delete the enumerated leases.