Search CVE reports


Toggle filters

1 – 10 of 70 results


CVE-2026-90460

Medium priority
Needs evaluation

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating,...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-80183

Medium priority
Needs evaluation

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-80184

Medium priority
Needs evaluation

In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-80182

Medium priority
Needs evaluation

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44394

Medium priority

Some fixes available 4 of 7

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-43000

Medium priority

Some fixes available 4 of 7

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-42999

Medium priority

Some fixes available 4 of 7

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-42998

Medium priority

Some fixes available 4 of 7

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-43001

Medium priority

Some fixes available 4 of 7

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential....

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-40683

Medium priority

Some fixes available 3 of 6

In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the...

1 affected package

keystone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Not affected Fixed Fixed Needs evaluation Needs evaluation
Show less packages