PT-2026-81866 · Openstack · Openstack Keystone

·

CVE-2026-80182

·

Published

2026-08-25

·

Updated

2026-08-26

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Keystone versions prior to 29.0.3
Description Tokens obtained through OAuth1 access tokens, application credentials, or trust-scoped authentication can be used to create new long-lived credentials or authorize new delegations. These new credentials persist independently and outlive the original token used to obtain them. This occurs because delegation restrictions are not consistently applied across all delegated token types, allowing an OAuth1-scoped token to create application credentials or authorize OAuth1 request tokens, even though such operations are restricted for other delegated token types.
Recommendations Update OpenStack Keystone to version 29.0.3 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80182

Affected Products

Openstack Keystone