https://seclists.org/oss-sec/2026/q2/37: [OSSA-2026-005] Keystone: stricted application cdentials can cate EC2 cdentials (CVE-2026-33551)
Published Apr 7, 2026
·Updated
Affected Software
1 affected component
Openstack Keystone>=14.0.0<26.1.1, =27.0.0, =28.0.0, =29.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-33551?
CVE-2026-33551 is considered a high severity vulnerability due to its potential to allow unauthorized EC2 credentials creation.
2
How do I fix CVE-2026-33551?
To fix CVE-2026-33551, update your OpenStack Keystone to the latest patched version as recommended by the vendor.
3
What systems are affected by CVE-2026-33551?
CVE-2026-33551 affects OpenStack Keystone specifically, allowing restricted application credentials to create EC2 credentials.
4
What is the impact of CVE-2026-33551?
The impact of CVE-2026-33551 is that it allows attackers to exploit restricted credentials to gain unauthorized access to EC2 resources.
5
When was CVE-2026-33551 published?
CVE-2026-33551 was published on April 07, 2026.