CVE-2026-93854
CVE-2026-93854 is a high-severity vulnerability with a CVSS 4.0 base score of 7.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1025.
Key facts
- Severity: High (CVSS 4.0 base score 7.2)
- EPSS exploit prediction: 0% (33rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1025
- Published:
- Last modified:
Description
In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper attempts to load the target lease to build the authorization target from its owner, but it looks up the lease under the keyword "lease_id" whereas the controller methods name the parameter "id" (and the wsme_pecan.wsexpose wrapper delivers it positionally). The lookup returns None, and thus authorization falls back to the requesting user's own project_id/user_id instead of the target lease owner. Any authenticated user who knows a lease ID can therefore modify or delete leases belonging to other users and projects, bypassing the intended ownership check.
Frequently asked questions
- What is CVE-2026-93854?
- In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper attempts to load the target lease to build the authorization target from its owner, but it looks up the lease under the keyword "lease_id" whereas the controller methods name the parameter "id" (and the wsme_pecan.wsexpose wrapper delivers it positionally). The lookup returns None, and thus authorization falls back to the requesting user's own project_id/user_id instead of the target lease owner. Any authenticated user who knows a lease ID can therefore modify or delete leases belonging to other users and projects, bypassing the intended ownership check.
- How severe is CVE-2026-93854?
- CVE-2026-93854 has a CVSS 4.0 base score of 7.2, rated high severity.
- Is CVE-2026-93854 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (33rd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-93854?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-93854 published?
- CVE-2026-93854 was published on 2026-09-18 and last updated on 2026-09-22.
References
Other CWE-1025 vulnerabilities
- CVE-2025-71377 — High (CVSS 8.7): stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching…
- CVE-2026-100248 — High (CVSS 8.4): The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.
- CVE-2026-9800 — High (CVSS 8.1): A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all…
- CVE-2026-40880 — High (CVSS 8.1): ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a…
- CVE-2026-29811 — High (CVSS 7.7): CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a…
- CVE-2023-54390 — High (CVSS 7.5): PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of service vulnerability in LoginPacket JSON parsing…