CVE-2026-93852

CVE-2026-93852 published: In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the Blazar REST API can enumerate le...

View full NVD advisory → ← Back to CVE watch