Cross-Tenant DNS Hijack Vulnerability in OpenStack Designate
⚠️ CVE-Referenzen:
CVE-2026-71193
Openstack - Designate - CRITICAL - CVE-2026-71193.
The vulnerability in OpenStack Designate prior to version 22.0.1 allows authenticated users to bypass essential zone creation checks. By leveraging the AttributeFilter scheduler, an attacker can configure a zone in a different target pool, leading to overlapping zones that can conflict with other tenants. This serious flaw facilitates cross-tenant DNS hijacking, where traffic can be redirected to IPs controlled by an attacker, and can also result in DNS denial of service via NODATA responses. Exploitation necessitates a setup with multiple pools and the AttributeFilter enabled, which, although not default, is documented for self-service tiering configurations.
Quelle: securityvulnerability.io