What is CVE-2026-71193?
CVE-2026-71193: In OpenStack Designate versions before 22.0.1, authenticated users can bypass zone creation checks by scheduling a zone to a different pool via the AttributeFilter scheduler, as the checks are scoped only to the target pool. This allows the creation of overlapping zones. Upgrading to version 22.0.1 or later is strongly recommended.
Azərbaycanca: CVE-2026-71193: OpenStack Designate-in 22.0.1-dən əvvəlki versiyalarında zona yoxlamaları yalnız hədəf hovuz (target pool) üzrə məhdudlaşdığı üçün autentifikasiyalı istifadəçi AttributeFilter planlayıcısı vasitəsilə zonanı fərqli hovuza yönləndirərək bu yoxlamalardan yan keçə bilir. Bu, "overlapping zone" (üst-üstə düşən zona) yaradılmasına imkan verir. Problemi aradan qaldırmaq üçün Designate-i ən azı 22.0.1 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: OpenStack
FAQ2
Which versions of OpenStack Designate are affected by CVE-2026-71193?
This vulnerability affects all versions of OpenStack Designate before 22.0.1. Upgrading to version 22.0.1 or later is strongly recommended.
How can an authenticated user bypass zone creation checks via CVE-2026-71193?
An authenticated user can bypass zone creation checks by scheduling a zone to a different pool via the AttributeFilter scheduler, as the checks are scoped only to the target pool. This allows the creation of overlapping zones.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.