Description
In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the Blazar REST API can enumerate leases belonging to other tenants, exposing lease IDs, reservation IDs, resource IDs, and reservation metadata. The exposed lease IDs also enable the object-level authorization bypass tracked in the companion request, allowing an attacker to then modify or delete the enumerated leases.
Published: 2026-09-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Lease Access and Potential Modification
Action: Apply Patch
AI Analysis

Impact

The vulnerability is in OpenStack Blazar’s V2 lease listing API. An authenticated user calling GET /v2/leases receives lease data for every project, because the request does not enforce project scoping or an administrator‑only policy. The exposed data includes lease IDs, reservation IDs, resource IDs, and reservation metadata, which together reveal sensitive scheduling information. The leaked lease IDs also satisfy a prerequisite for a later object‑level authorization bypass, letting an attacker modify or delete leases that belong to other tenants. This flaw therefore enables both information disclosure and potential tampering with resources across projects.

Affected Systems

All installations of OpenStack Blazar earlier than version 17.0.1 are affected. In particular, the reference update to 17.0.1 contains the fix for the lease listing path.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity. The EPSS score is below 1%, pointing to a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by authenticating to the Blazar REST API and issuing a simple GET request, which is typical for authenticated users. The lack of a policy check makes the attack trivial for any credentialed user. However, because the flaw also enables later modification via object‑level bypass, the combined impact is significant when used with the accompanying exploit.

Generated by OpenCVE AI on September 19, 2026 at 16:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenStack Blazar to version 17.0.1 or later, which enforces project scoping on lease listings.
  • If an upgrade is not immediately possible, restrict REST API access to administrators or network segments that host service accounts, to limit enumeration by ordinary tenants.
  • Re‑evaluate and apply correct policies on the lease listing endpoint to enforce project boundaries even if an upgrade is delayed.
  • Document and monitor access to the Lease API, and audit for anomalous enumeration activity.

Generated by OpenCVE AI on September 19, 2026 at 16:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Openstack
Openstack blazar
Vendors & Products Openstack
Openstack blazar

Sat, 19 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title OpenStack Blazar Lease Enumeration and Modification via Unrestricted Lease Listing

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the Blazar REST API can enumerate leases belonging to other tenants, exposing lease IDs, reservation IDs, resource IDs, and reservation metadata. The exposed lease IDs also enable the object-level authorization bypass tracked in the companion request, allowing an attacker to then modify or delete the enumerated leases.
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Openstack Blazar
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-18T19:47:14.422Z

Reserved: 2026-09-18T18:48:34.492Z

Link: CVE-2026-93852

cve-icon Vulnrichment

Updated: 2026-09-18T19:47:10.976Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T19:17:25.267

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-93852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:28:32Z

Weaknesses