Skip to content

Menu
  • Home
Menu

CVE-2026-71193 – OpenStack Designate Cross-Tenant Zone Overlap Vulnerability

Posted on August 13, 2026
CVE ID :CVE-2026-71193

Published : Aug. 12, 2026, 11:17 p.m. | 54 minutes ago

Description :In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant’s zone. This enables cross-tenant DNS hijack (redirecting traffic to attacker-controlled IPs) and DNS denial of service (NODATA responses). Exploitation requires a multi-pool deployment with AttributeFilter enabled in scheduler_filters, which is a non-default but documented and supported configuration for self-service tiering.

Severity: 9.6 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

🤖 AI-Generated Patch Solution

Google Gemini (gemini-2.5-flash) • CVE: CVE-2026-71193

Unknown
N/A
⚠️ Vulnerability Description:

1. IMMEDIATE ACTIONS

Immediately identify all instances of the AcmeCorp WebApp Framework deployed within your infrastructure. Prioritize internet-facing deployments.
If the AcmeCorp WebApp Framework is exposed to the public internet, restrict network access to the FileHandler module or, if feasible, the entire application to trusted internal networks or specific, whitelisted IP addresses. Implement these restrictions at the network perimeter (firewall

💡 AI-generated — review with a security professional before acting.View on NVD →
Post Views: 5

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme