OpenStack Blazar <17.0.1: Lease Enumeration & Auth Bypass via GET /v2/leases
CVE-2026-93852 Published on September 18, 2026
In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the Blazar REST API can enumerate leases belonging to other tenants, exposing lease IDs, reservation IDs, resource IDs, and reservation metadata. The exposed lease IDs also enable the object-level authorization bypass tracked in the companion request, allowing an attacker to then modify or delete the enumerated leases.
Vulnerability Analysis
CVE-2026-93852 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-93852 has been classified to as an AuthZ vulnerability or weakness.
Affected Versions
OpenStack Blazar:- Version 1.0.0 and below 15.1.1 is affected.
- Version 16.0.0 and below 16.0.1 is affected.
- Version 17.0.0 and below 17.0.1 is affected.