REDHAT-BUG-2451037: Low severity Openstack Keystone vulnerability

Published Mar 25, 2026
·
Updated

Maxence Bornecque from Orange Cyberdefense CERT Vulnerability Intelligence Watch Team reported a vulnerability in Keystone's EC2 credential creation endpoint. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.

Affected Software

1 affected component
Openstack Keystone

Event History

Mar 25, 2026
Data Sourced
via Red Hat·12:11 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2451037?

The severity of REDHAT-BUG-2451037 is classified as low.

2

How do I fix REDHAT-BUG-2451037?

To remediate REDHAT-BUG-2451037, restrict access to the EC2 credential creation endpoint by adjusting user roles and permissions.

3

What software is affected by REDHAT-BUG-2451037?

The vulnerability REDHAT-BUG-2451037 affects OpenStack Keystone.

4

Who reported REDHAT-BUG-2451037?

REDHAT-BUG-2451037 was reported by Maxence Bornecque from the Orange Cyberdefense CERT Vulnerability Intelligence Watch Team.

5

What is the description of REDHAT-BUG-2451037?

REDHAT-BUG-2451037 concerns a vulnerability that allows an authenticated user with a reader role to exploit the EC2 credential creation API using a restricted application credential.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203