CVE-2026-43001: [OSSA-2026-015] OpenStack Keystone: Multiple cdential delegation and authorization bypass vulnerabilities (CVE-2026-42998, CVE-2026-42999, CVE-2026-43000, CVE-2026-43001, CVE-2026-44394)
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied projectid for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original appcredid, enabling cross-project lateral movement within the credential owner's role footprint.
Other sources
An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied projectid for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original appcredid, enabling cross-project lateral movement within the credential owner's role footprint.
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/keystoneto a version that resolves this vulnerability.Fixed in 2:18.1.0-1+deb11u3Fixed in 2:22.0.2-0+deb12u3Fixed in 2:27.0.0-3+deb13u4Fixed in 2:29.0.1-2 - Upgrade
Upgrade
openstack/keystoneto a version that resolves this vulnerability.Fixed in 29.0.2Patch OSSA-2026-015 - Upgrade
Upgrade
openstack/keystoneto a version that resolves this vulnerability.Fixed in 29.0.1Patch OSSA-2026-015
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43001?
CVE-2026-43001 is considered a high severity vulnerability due to the potential for unauthorized access to project credentials.
How do I fix CVE-2026-43001?
To fix CVE-2026-43001, upgrade OpenStack Keystone to a version newer than 29, where the issue has been resolved.
What versions of OpenStack Keystone are affected by CVE-2026-43001?
OpenStack Keystone versions 13 through 29 are affected by CVE-2026-43001.
What impact does CVE-2026-43001 have on application security?
CVE-2026-43001 could allow attackers to exploit unrestricted credentials, compromising the integrity of the project associated with them.
Is there a workaround for CVE-2026-43001 if upgrading is not possible?
There are no documented workarounds for CVE-2026-43001; the best mitigation is to apply the necessary upgrades.