[OSSA-2026-040] OpenStack Blazar: Multiple authorization vulnerabilities in the Blazar V2 lease API (CVE-2026-93852, CVE-2026-93854)
OpenStack Blazar's V2 lease API has authorization flaws CVE-2026-93852 and CVE-2026-93854.
OpenStack published OSSA-2026-040 on September 21, 2026, describing multiple authorization vulnerabilities in the Blazar V2 lease API. CVE-2026-93852 and CVE-2026-93854 affect Blazar from 1.0.0 before 15.1.1, as well as versions 16.0.0 and 17.0.0. Rohan Das is credited with the report. The disclosure does not say the flaws are being exploited.
46