https://seclists.org/oss-sec/2026/q2/722: [OSSA-2026-015] OpenStack Keystone: Multiple cdential delegation and authorization bypass vulnerabilities (CVE-2026-42998, CVE-2026-42999, CVE-2026-43000, CVE-2026-43001, CVE-2026-44394)
Published May 28, 2026
·Updated
Affected Software
1 affected component
Openstack Keystone>=14.0.0<27.0.2, >=28.0.0<28.0.2, >=29.0.0<29.0.2
Frequently Asked Questions
1
What is the severity of CVE-2026-42998?
CVE-2026-42998 is rated as a high severity vulnerability affecting OpenStack Keystone.
2
How do I fix CVE-2026-42999?
To fix CVE-2026-42999, upgrade to the latest version of OpenStack Keystone with the appropriate security patches applied.
3
What impact does CVE-2026-43000 have on my OpenStack Keystone deployment?
CVE-2026-43000 allows unauthorized access which can compromise credential delegation and authorization processes.
4
Are there any workarounds for CVE-2026-43001?
Currently, there are no recommended workarounds for CVE-2026-43001, and updating Keystone is the best mitigation.
5
What vulnerabilities does CVE-2026-44394 address?
CVE-2026-44394 addresses authorization bypass vulnerabilities that can lead to unauthorized access in OpenStack Keystone.