Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Xek

Researcher fromRed Hat
#36395of 56,328
7.6Total CVSS
Vulnerabilities · 1
PT-2026-81866
7.6
2026-08-25
Openstack · Openstack Keystone · CVE-2026-80182
**Name of the Vulnerable Software and Affected Versions** OpenStack Keystone versions prior to 29.0.3 **Description** Tokens obtained through OAuth1 access tokens, application credentials, or trust-scoped authentication can be used to create new long-lived credentials or authorize new delegations. These new credentials persist independently and outlive the original token used to obtain them. This occurs because delegation restrictions are not consistently applied across all delegated token types, allowing an OAuth1-scoped token to create application credentials or authorize OAuth1 request tokens, even though such operations are restricted for other delegated token types. **Recommendations** Update OpenStack Keystone to version 29.0.3 or later.