Cross-Tenant DNS Hijack Vulnerability in OpenStack Designate
CVE-2026-71193
9.6CRITICAL
What is CVE-2026-71193?
The vulnerability in OpenStack Designate prior to version 22.0.1 allows authenticated users to bypass essential zone creation checks. By leveraging the AttributeFilter scheduler, an attacker can configure a zone in a different target pool, leading to overlapping zones that can conflict with other tenants. This serious flaw facilitates cross-tenant DNS hijacking, where traffic can be redirected to IPs controlled by an attacker, and can also result in DNS denial of service via NODATA responses. Exploitation necessitates a setup with multiple pools and the AttributeFilter enabled, which, although not default, is documented for self-service tiering configurations.
Affected Version(s)
Designate 1.0.0 < 20.0.2
Designate 21.0.0 < 21.0.1
Designate 22.0.0 < 22.0.1
