CRITICAL

CVE-2026-71193

Cross‑Tenant DNS Hijack and Denial of Service via Designate Zone Creation

CVSS v3

9.6

CRITICAL

EPSS Score

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redirecting traffic to attacker-controlled IPs) and DNS denial of service (NODATA responses). Exploitation

Technical details

CVSS v3 Vector
3.1
Published
8/12/2026
Last Modified
8/12/2026

Frequently asked questions

What is CVE-2026-71193?

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redirecting traffic to attacker-controlled IPs) and DNS denial of service (NODATA responses). Exploitation

Is CVE-2026-71193 actively exploited?

Active exploitation of CVE-2026-71193 has not been confirmed. The EPSS score is N/A%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-71193?

CVE-2026-71193 has a CVSS v3 base score of 9.6 (CRITICAL severity), with vector string 3.1.

Is CVE-2026-71193 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.