CVE-2026-71193: CWE-863 Incorrect Authorization in OpenStack Designate
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redirecting traffic to attacker-controlled IPs) and DNS denial of service (NODATA responses). Exploitation requires a multi-pool deployment with AttributeFilter enabled in scheduler_filters, which is a non-default but documented and supported configuration for self-service tiering.
AI Analysis
Technical Summary
OpenStack Designate versions 1.0.0, 21.0.0, and 22.0.0 are affected by an incorrect authorization vulnerability (CWE-863) where zone creation checks are scoped only to the target pool. An authenticated user can exploit this by scheduling a zone to a different pool using the AttributeFilter scheduler, which is a supported but non-default configuration. This enables the creation of overlapping zones that conflict with other tenants' zones, resulting in cross-tenant DNS hijack and DNS denial of service (NODATA responses). The vulnerability requires a multi-pool deployment with AttributeFilter enabled in scheduler_filters. The CVSS 3.1 base score is 9.6, indicating critical severity with network attack vector, low attack complexity, and requiring low privileges but no user interaction.
Potential Impact
The vulnerability allows an authenticated attacker to bypass authorization checks and create overlapping DNS zones in other tenants' pools. This can lead to DNS hijacking, redirecting traffic to attacker-controlled IP addresses, and DNS denial of service by causing NODATA responses. The impact affects confidentiality and integrity of DNS data across tenants and availability of DNS services.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should consider disabling the AttributeFilter scheduler or avoid multi-pool deployments with this configuration to mitigate the risk. Monitoring for unauthorized zone creations in multi-tenant environments is advised.
CVE-2026-71193: CWE-863 Incorrect Authorization in OpenStack Designate
Description
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redirecting traffic to attacker-controlled IPs) and DNS denial of service (NODATA responses). Exploitation requires a multi-pool deployment with AttributeFilter enabled in scheduler_filters, which is a non-default but documented and supported configuration for self-service tiering.
CVSS v3.1
Score 9.6critical
Affected software
OpenStack
Designate
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenStack Designate versions 1.0.0, 21.0.0, and 22.0.0 are affected by an incorrect authorization vulnerability (CWE-863) where zone creation checks are scoped only to the target pool. An authenticated user can exploit this by scheduling a zone to a different pool using the AttributeFilter scheduler, which is a supported but non-default configuration. This enables the creation of overlapping zones that conflict with other tenants' zones, resulting in cross-tenant DNS hijack and DNS denial of service (NODATA responses). The vulnerability requires a multi-pool deployment with AttributeFilter enabled in scheduler_filters. The CVSS 3.1 base score is 9.6, indicating critical severity with network attack vector, low attack complexity, and requiring low privileges but no user interaction.
Potential Impact
The vulnerability allows an authenticated attacker to bypass authorization checks and create overlapping DNS zones in other tenants' pools. This can lead to DNS hijacking, redirecting traffic to attacker-controlled IP addresses, and DNS denial of service by causing NODATA responses. The impact affects confidentiality and integrity of DNS data across tenants and availability of DNS services.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should consider disabling the AttributeFilter scheduler or avoid multi-pool deployments with this configuration to mitigate the risk. Monitoring for unauthorized zone creations in multi-tenant environments is advised.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-08-05T05:09:31.046Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7cf6b1bf8831d539443f5d
Added to database: 08/12/2026, 22:41:53 UTC
Last enriched: 08/12/2026, 22:56:09 UTC
Last updated: 09/27/2026, 01:47:44 UTC
Views: 115
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.