CVE-2026-93854

CVE-2026-93854 published: In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper attempts to load the target leas...

View full NVD advisory → ← Back to CVE watch