CVE-2026-93852

NameCVE-2026-93852
DescriptionIn OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the Blazar REST API can enumerate leases belonging to other tenants, exposing lease IDs, reservation IDs, resource IDs, and reservation metadata. The exposed lease IDs also enable the object-level authorization bypass tracked in the companion request, allowing an attacker to then modify or delete the enumerated leases.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1148408

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
blazar (PTS)trixie15.0.0-3vulnerable
forky, sid18.0.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
blazarsource(unstable)18.0.0~rc1-31148408

Notes

[trixie] - blazar <no-dsa> (Minor issue)
https://launchpad.net/bugs/2162719
https://security.openstack.org/ossa/OSSA-2026-040.html

Search for package or bug name: Reporting problems