Junglewise Threat Intelligence

CVE-2026-93854: OpenStack Blazar authorization bypass in Lease API

CVE-2026-93854 · Severity: info · Published 2026-09-18

Vendors: OpenStack.

Executive brief

OpenStack Blazar manages and schedules cloud computing resources across a pool of machines. An authenticated user can modify or delete leases belonging to other users and projects due to a parameter naming mismatch that breaks the authorization check. This allows attackers who know a lease ID to bypass ownership controls and sabotage or steal compute resource allocations.

Technical details

The Blazar V2 Lease API (PUT and DELETE on /v2/leases/{lease_id}) uses a policy authorization wrapper that attempts to load the target lease using kwargs.get("lease_id") to construct the authorization target with the lease owner's project and user IDs. However, the controller methods define the parameter as "id" rather than "lease_id", causing the lookup to return None and authorization to fall back to the authenticated requester's own project/user context instead of the target lease owner. Any authenticated user can bypass object-level authorization by knowing a lease ID, exploiting CWE-639 (Authorization Bypass Through User-Controlled Key).

Affected products

  • OpenStack Blazar before 17.0.1

Timeline

  • 2026-09-18: disclosed: Published on NVD
  • 2026-08-03: other: Bug reported on Launchpad as OSSA-2026-040

References

Related threats