CVE-2026-33551: [OSSA-2026-005] Keystone: stricted application cdentials can cate EC2 cdentials (CVE-2026-33551)
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.
Other sources
Maxence Bornecque from Orange Cyberdefense CERT Vulnerability Intelligence Watch Team reported a vulnerability in Keystone's EC2 credential creation endpoint. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/keystoneto a version that resolves this vulnerability.Fixed in 2:18.1.0-1+deb11u3Fixed in 2:22.0.2-0+deb12u3Fixed in 2:27.0.0-3+deb13u4Fixed in 2:29.0.1-2 - Upgrade
Upgrade
OpenStack Keystoneto a version that resolves this vulnerability.Fixed in 26.1.1Patch OSSA-2026-005 - Upgrade
Upgrade
OpenStack Keystoneto a version that resolves this vulnerability.Fixed in 27.0.0Patch OSSA-2026-005 - Upgrade
Upgrade
OpenStack Keystoneto a version that resolves this vulnerability.Fixed in 28.0.0Patch OSSA-2026-005 - Upgrade
Upgrade
OpenStack Keystoneto a version that resolves this vulnerability.Fixed in 29.0.0Patch OSSA-2026-005 - Compensating control
Only deployments that use restricted application credentials together with the EC2/S3 compatibility API (swift3/s3api) are affected; for affected deployments, restrict/limit access to the EC2 credential creation API (EC2/S3 compatibility endpoints) to trusted users/roles until Keystone is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33551?
CVE-2026-33551 has been assigned a high severity rating due to the potential for unauthorized access to EC2 credentials.
How do I fix CVE-2026-33551?
To fix CVE-2026-33551, upgrade OpenStack Keystone to version 26.1.1 or later, or to version 27.0.0, 28.0.0, or 29.0.0.
What versions of OpenStack Keystone are affected by CVE-2026-33551?
CVE-2026-33551 affects OpenStack Keystone versions 14 through 26 before 26.1.1, as well as versions 27.0.0, 28.0.0, and 29.0.0.
What kind of access can be gained through CVE-2026-33551?
CVE-2026-33551 allows restricted application credentials to create EC2 credentials, potentially enabling unauthorized resource access.
Is CVE-2026-33551 related to any specific OpenStack features?
CVE-2026-33551 is specifically related to the management of application credentials within OpenStack Keystone.