[OSSA-2026-040] OpenStack Blazar: Multiple authorization vulnerabilities in the Blazar V2 lease API (CVE-2026-93852, CVE-2026-93854)
OpenStack Blazar's V2 lease API has authorization flaws CVE-2026-93852 and CVE-2026-93854.
OpenStack published OSSA-2026-040 on September 21, 2026, describing multiple authorization vulnerabilities in the Blazar V2 lease API. CVE-2026-93852 and CVE-2026-93854 affect Blazar from 1.0.0 before 15.1.1, as well as versions 16.0.0 and 17.0.0. Rohan Das is credited with the report. The disclosure does not say the flaws are being exploited.
- OSSA-2026-040 covers two authorization flaws in the Blazar V2 lease API.
- Affected releases are 1.0.0 through before 15.1.1, plus 16.0.0 and 17.0.0.
- CVEs are CVE-2026-93852 and CVE-2026-93854; active exploitation is not reported.
Vulnerabilities mentionedAll →
- CVE-2026-938527.1—Missing authorization in OpenStack Blazar exposes leases across all tenantspublished · OpenStack Foundation OpenStack Blazar
- CVE-2026-938547.2—Broken Object-Level Authorization in OpenStack Blazar Lease APIpublished · OpenStack Blazar
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected |
|---|
Posted by Goutham Pacha Ravi on Sep 21 ================================================================================ OSSA-2026-040: Multiple authorization vulnerabilities in the Blazar V2 lease API ================================================================================ :Date: September 21, 2026 :CVE: CVE-2026-93852, CVE-2026-93854 Affects ~~~~~~~ - Blazar: >=1.0.0 <15.1.1, ==16.0.0, ==17.0.0 Description ~~~~~~~~~~~ Rohan Das from the University of...
This source does not provide full text. Read it at seclists.org.