OpenStack Blazar Vulnerability Exposing Lease Information
CVE-2026-93852

7.1HIGH

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-93852?

In OpenStack Blazar versions prior to 17.0.1, there exists a vulnerability in the V2 lease listing operation which allows authenticated users to access lease information across all projects. This flaw permits users to enumerate lease IDs, reservation IDs, resource IDs, and reservation metadata belonging to other tenants without proper project scoping or security controls. The exposure of lease IDs can lead to further security breaches, including unauthorized modifications or deletions of leases, thus posing significant risks to resource integrity and privacy.

Affected Version(s)

Blazar 1.0.0 < 15.1.1

Blazar 16.0.0 < 16.0.1

Blazar 17.0.0 < 17.0.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.