CVE-2026-33551: [OSSA-2026-005] Keystone: stricted application cdentials can cate EC2 cdentials (CVE-2026-33551)

Published Mar 25, 2026
·
Updated

An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.

Other sources

Maxence Bornecque from Orange Cyberdefense CERT Vulnerability Intelligence Watch Team reported a vulnerability in Keystone's EC2 credential creation endpoint. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.

Red Hat

Affected Software

6 affected componentsFixes available
Openstack Keystone>=14<26.1.1, =27.0.0, =28.0.0, =29.0.0
Openstack Keystone>=14.0.0<26.1.1
Openstack Keystone=27.0.0
Openstack Keystone=28.0.0
Openstack Keystone=29.0.0
debian/keystone<=2:18.0.0-3+deb11u1, <=2:22.0.2-0+deb12u1, <=2:27.0.0-3+deb13u1
2:18.1.0-1+deb11u32:22.0.2-0+deb12u32:27.0.0-3+deb13u42:29.0.1-2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/keystone to a version that resolves this vulnerability.

    Fixed in 2:18.1.0-1+deb11u3Fixed in 2:22.0.2-0+deb12u3Fixed in 2:27.0.0-3+deb13u4Fixed in 2:29.0.1-2
  2. Upgrade

    Upgrade OpenStack Keystone to a version that resolves this vulnerability.

    Fixed in 26.1.1Patch OSSA-2026-005
  3. Upgrade

    Upgrade OpenStack Keystone to a version that resolves this vulnerability.

    Fixed in 27.0.0Patch OSSA-2026-005
  4. Upgrade

    Upgrade OpenStack Keystone to a version that resolves this vulnerability.

    Fixed in 28.0.0Patch OSSA-2026-005
  5. Upgrade

    Upgrade OpenStack Keystone to a version that resolves this vulnerability.

    Fixed in 29.0.0Patch OSSA-2026-005
  6. Compensating control

    Only deployments that use restricted application credentials together with the EC2/S3 compatibility API (swift3/s3api) are affected; for affected deployments, restrict/limit access to the EC2 credential creation API (EC2/S3 compatibility endpoints) to trusted users/roles until Keystone is upgraded.

Event History

Mar 25, 2026
Data Sourced
via Red Hat·12:11 AM
DescriptionSeverityAffected Software
Apr 10, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 16, 2026
Data Sourced
via Launchpad·08:41 PM
Description
Data Sourced
via Debian·08:41 PM
DescriptionAffected Software
Jun 18, 2026
Data Sourced
via Ubuntu·08:42 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-33551?

CVE-2026-33551 has been assigned a high severity rating due to the potential for unauthorized access to EC2 credentials.

2

How do I fix CVE-2026-33551?

To fix CVE-2026-33551, upgrade OpenStack Keystone to version 26.1.1 or later, or to version 27.0.0, 28.0.0, or 29.0.0.

3

What versions of OpenStack Keystone are affected by CVE-2026-33551?

CVE-2026-33551 affects OpenStack Keystone versions 14 through 26 before 26.1.1, as well as versions 27.0.0, 28.0.0, and 29.0.0.

4

What kind of access can be gained through CVE-2026-33551?

CVE-2026-33551 allows restricted application credentials to create EC2 credentials, potentially enabling unauthorized resource access.

5

Is CVE-2026-33551 related to any specific OpenStack features?

CVE-2026-33551 is specifically related to the management of application credentials within OpenStack Keystone.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203