CVE-2026-44394: [OSSA-2026-015] OpenStack Keystone: Multiple cdential delegation and authorization bypass vulnerabilities (CVE-2026-42998, CVE-2026-42999, CVE-2026-43000, CVE-2026-43001, CVE-2026-44394)
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handlescopedtoken() function in the mapped authentication plugin returns response data without an expiresat value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/keystoneto a version that resolves this vulnerability.Fixed in 2:18.1.0-1+deb11u3Fixed in 2:22.0.2-0+deb12u3Fixed in 2:27.0.0-3+deb13u4Fixed in 2:29.0.1-2 - Upgrade
Upgrade
debian/keystoneto a version that resolves this vulnerability.Fixed in 2:18.1.0-1+deb11u3 - Upgrade
Upgrade
debian/keystoneto a version that resolves this vulnerability.Fixed in 2:22.0.2-0+deb12u3 - Upgrade
Upgrade
debian/keystoneto a version that resolves this vulnerability.Fixed in 2:27.0.0-3+deb13u4 - Upgrade
Upgrade
debian/keystoneto a version that resolves this vulnerability.Fixed in 2:29.0.1-2 - Configuration
If federated identity (SAML2 or OpenID Connect) is not required, disable federated authentication to avoid exposure to the federated token rescoping issue.
OpenStack Keystone (federated identity) federated_identity (SAML2, OpenID Connect) = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44394?
CVE-2026-44394 has a medium severity rating of 6.
What vulnerabilities are related to CVE-2026-44394?
CVE-2026-44394 is part of a group of vulnerabilities including CVE-2026-42998, CVE-2026-42999, CVE-2026-43000, and CVE-2026-43001.
How do I fix CVE-2026-44394?
To address CVE-2026-44394, upgrade OpenStack Keystone to version 29.0.2 or later.
What is the impact of CVE-2026-44394 on OpenStack Keystone?
CVE-2026-44394 can lead to credential delegation and authorization bypass due to improper token expiry propagation.
When was CVE-2026-44394 published?
CVE-2026-44394 was published on May 28, 2026.