CVE-2026-93852 Overview
CVE-2026-93852 is a missing authorization vulnerability [CWE-862] in OpenStack Blazar before version 17.0.1. The GET /v2/leases endpoint returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the Blazar REST API can enumerate leases belonging to other tenants. The exposed data includes lease IDs, reservation IDs, resource IDs, and reservation metadata. The disclosed lease identifiers also enable a companion object-level authorization bypass, allowing an attacker to modify or delete the enumerated leases.
Critical Impact
Authenticated tenants can enumerate and, through a companion flaw, tamper with leases owned by other projects across the OpenStack deployment.
Affected Products
- OpenStack Blazar reservation service
- All Blazar releases prior to 17.0.1
- OpenStack deployments exposing the Blazar V2 REST API to tenants
Discovery Timeline
- 2026-09-18 - CVE-2026-93852 published to the National Vulnerability Database (NVD)
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2026-93852
Vulnerability Analysis
Blazar is the OpenStack reservation service that manages leases for compute hosts, instances, and floating IPs. The V2 lease listing operation exposes a REST endpoint intended to return leases that belong to the caller's project. In vulnerable releases, the controller responsible for GET /v2/leases returns all leases in the database without filtering by the requester's project identifier and without requiring an administrator role.
The flaw is a classic missing authorization defect. The service authenticates the Keystone token but then skips the tenancy check that other OpenStack projects apply through oslo.policy rules such as rule:admin_or_owner. As a result, cross-tenant reservation metadata leaks to any principal with Blazar API access.
Because Blazar leases reference concrete resources, the exposed identifiers describe the reservation topology of neighboring tenants. Combined with the companion object-level authorization bypass, the leaked lease IDs become direct handles for destructive UPDATE and DELETE operations against other projects' reservations.
Root Cause
The root cause is an absent policy enforcement point in the V2 leases collection handler. The list operation neither scopes the database query by project_id nor gates the response behind an administrator-only policy. This maps to [CWE-862] Missing Authorization.
Attack Vector
Exploitation requires network reachability to the Blazar API and a valid Keystone token for any project. The attacker issues a standard authenticated GET request against /v2/leases and parses the JSON response for lease and reservation identifiers belonging to other tenants. No user interaction is required and the attack complexity is low.
The vulnerability is described in the Launchpad Bug Report #2162719. No public proof-of-concept exploit is currently listed for this CVE.
Detection Methods for CVE-2026-93852
Indicators of Compromise
- Repeated GET /v2/leases requests from a single tenant token followed by targeted PUT or DELETE operations against lease IDs that do not belong to that tenant's project.
- Blazar API responses containing lease objects whose project_id field does not match the requesting principal's project scope.
- Unexpected lease deletions or modifications in the Blazar database that do not correlate with owning-tenant activity.
Detection Strategies
- Enable Blazar API access logging and correlate the X-Project-Id header of the caller against the project_id of each lease returned in the response body.
- Alert on any successful GET /v2/leases response volume that exceeds the number of leases actually owned by the calling project.
- Compare Keystone audit events with Blazar action logs to identify cross-project reservation access patterns.
Monitoring Recommendations
- Forward Blazar and Keystone logs to a centralized analytics platform for cross-service correlation.
- Track authentication tokens that enumerate leases followed by write operations within a short time window.
- Baseline normal per-tenant lease listing volumes and alert on statistical deviations.
How to Mitigate CVE-2026-93852
Immediate Actions Required
- Upgrade OpenStack Blazar to version 17.0.1 or later on all controller nodes running the blazar-api service.
- Audit Blazar and Keystone logs for prior cross-tenant GET /v2/leases activity and any subsequent lease modifications.
- Rotate lease and reservation identifiers where feasible and validate the integrity of active reservations across tenants.
Patch Information
The issue is fixed in OpenStack Blazar 17.0.1. Operators should track the upstream fix through the Launchpad Bug Report #2162719 and apply distribution-provided packages once available. Verify the installed version with pip show blazar or the equivalent package manager query on the controller.
Workarounds
- Restrict network access to the Blazar API endpoint to trusted administrative networks until the patch is deployed.
- Override the Blazar policy.yaml for the blazar:leases:get action to require rule:context_is_admin, denying non-administrator list access.
- Disable or firewall the /v2/leases route at the API gateway layer if the reservation service is not actively used.
# Example Blazar policy.yaml override restricting lease listing to administrators
"blazar:leases:get": "rule:context_is_admin"
"blazar:leases:get_all": "rule:context_is_admin"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
