CVE-2026-71193
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redirecting traffic to attacker-controlled IPs) and DNS denial of service (NODATA responses). Exploitation requires a multi-pool deployment with AttributeFilter enabled in scheduler_filters, which is a non-default but documented and supported configuration for self-service tiering.
CSIRTS triage
- What
- Tenants can manipulate DNS zones belonging to other tenants, enabling denial of service or DNS hijacking.
- Who is affected
- OpenStack Designate deployments allowing multi-tenant DNS zone configuration.
- Urgency
- Critical due to potential for DNS hijacking and cross-tenant denial of service; no exploitation status reported.
- Action
- Apply Debian security update DSA-6452-1 or equivalent patches for CVE-2026-71193 and CVE-2026-71194.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-71193
Get an email if CVE-2026-71193 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownDSA-6452-1 designate - security updatedebian · 2026-08-19
- criticalCVE-2026-71193: In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and th…nvd · 2026-08-12
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-71193)