CVE-2026-71193
Received Received - Intake

DNS Hijacking in OpenStack Designate via Pool Misconfiguration

Vulnerability report for CVE-2026-71193, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: MITRE

Description

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redirecting traffic to attacker-controlled IPs) and DNS denial of service (NODATA responses). Exploitation requires a multi-pool deployment with AttributeFilter enabled in scheduler_filters, which is a non-default but documented and supported configuration for self-service tiering.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openstack designate to 22.0.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in OpenStack Designate before 22.0.1 allows an authenticated user to bypass zone creation checks by scheduling a zone to a different pool via the AttributeFilter scheduler. This creates an overlapping zone that conflicts with another tenant's zone, enabling cross-tenant DNS hijacking or denial of service.

Impact Analysis

An attacker could redirect traffic to malicious IPs (DNS hijacking) or cause denial of service by returning NODATA responses. This requires a multi-pool deployment with AttributeFilter enabled in scheduler_filters.

Mitigation Strategies

Upgrade OpenStack Designate to version 22.0.1 or later to address the zone creation checks bypass vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71193. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart