VYPR

Blazar V2 lease API

by OpenStack

CVEs (1)

  • CVE-2026-93854HigSep 18, 2026
    risk 0.47cvss epss

    In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper attempts to load the target lease to build the…

VYPR — Vulnerability Intelligence