CVE-2026-80183: High severity Openstack Keystone vulnerability

Published Aug 26, 2026
·
Updated

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with includesubtree to the GET /v3/roleassignments endpoint. The domain's project record has domainid=null, causing the policy domainid check to pass for any caller. With includenames, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in

listroleassignmentsfortree.

Affected Software

1 affected component
Openstack Keystone<29.0.3

Event History

Aug 26, 2026
CVE Published
via MITRE·11:16 PM
Data Sourced
via MITRE·11:16 PM
DescriptionWeakness
Aug 27, 2026
Data Sourced
via NVD·01:18 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which users can exploit this issue?

Any authenticated user with the reader role on any project can exploit it. The role does not need to be associated with the domain whose role assignments are queried.

2

Are standard Keystone deployments affected without knowing a target domain ID?

Deployments created with keystone-manage bootstrap can be queried using the literal domain ID "default." The response can then reveal additional domain IDs that can be used to enumerate role assignments across the cloud.

3

What information can be exposed?

Using include_names exposes the names and home-domain IDs of users, groups, projects, and roles in the returned project-scoped role assignments. This can allow an attacker to map role relationships across domains.

4

What request pattern indicates attempted exploitation?

The affected API is GET /v3/role_assignments with a domain ID supplied through scope.project.id and include_subtree enabled. Requests that also include include_names are intended to retrieve identifying details for the returned assignments.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203