CVE-2026-33551
published 2026-04-10CVE-2026-33551: An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2…
PriorityP431medium5.3CVSS 3.1
AVNACHPRLUINSUCHINAN
EPSS
0.22%
12.3th percentile
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | >= 14.0.0 < 26.1.1 | 26.1.1 |
| openstack | keystone | >= 14.0.0 < 26.1.1 | 26.1.1 |
| ubuntu | keystone | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_ubuntu5.3MEDIUM
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2026-06-16·CVSS 5.3
CVE-2026-44394 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Several security issues were fixed in OpenStack Keystone.
It was discovered that OpenStack Keystone allowed restricted application
credentials to create EC2 credentials. An authenticated attacker with only
a reader role could possibly use this issue to bypass the role restrictions
imposed on the application credential. (CVE-2026-33551)
It was discovered that the OpenStack Keystone LDAP identity backend did
not correctly convert the user enabled attribute to a boolean value.
An attacker could possibly use this issue to authenticate as a user disabled
in LDAP. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
and Ubuntu 25.10. (CVE-2026-40683)
It was discovered that OpenStack Keystone's application credential
authentication pl
Red Hat
openstack-keystone: OpenStack Keystone: Privilege escalation through EC2 credential creation
vendor_redhat·2026-04-07·CVSS 3.5
CVE-2026-33551 [LOW] CWE-266 openstack-keystone: OpenStack Keystone: Privilege escalation through EC2 credential creation
openstack-keystone: OpenStack Keystone: Privilege escalation through EC2 credential creation
A flaw was found in OpenStack Keystone. An authenticated user with a reader role can exploit a vulnerability in the EC2 credential creation endpoint. By using a restricted application credential to call the EC2 credential creation API, the user may obtain EC2/S3 credentials that carry the full set of the parent user's S3 permissions. This effectively bypasses the role restrictions imposed on the application credential, leading to unauthorized access and privilege escalation. This issue affects deployments that use restricted application credentials in combination with the EC2/S3 compatibility API.
Package: rhosp13/openstack-keystone (Red Hat OpenStack Platform 13 (Queens)) - Affected
Package: op
Debian
CVE-2026-33551: keystone
vendor_debian·2026·CVSS 3.5
CVE-2026-33551 [LOW] CVE-2026-33551: keystone
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
VulDB
Keystone up to 26.1.0/27.0.0/28.0.0/29.0.0 EC2 Credential Creation Endpoint improper authorization (Nessus ID 305614)
vuldb·2026-04-13·CVSS 3.5
CVE-2026-33551 [LOW] Keystone up to 26.1.0/27.0.0/28.0.0/29.0.0 EC2 Credential Creation Endpoint improper authorization (Nessus ID 305614)
A vulnerability categorized as critical has been discovered in Keystone up to 26.1.0/27.0.0/28.0.0/29.0.0. Affected is an unknown function of the component EC2 Credential Creation Endpoint. Executing a manipulation can lead to improper authorization.
The identification of this vulnerability is CVE-2026-33551. The attack may be launched remotely. There is no exploit available.
It is best practice to apply a patch to resolve this issue.
GHSA
GHSA-4phw-6824-6cfp: An issue was discovered in OpenStack Keystone 14 through 26 before 26
ghsa_unreviewed·2026-04-10
CVE-2026-33551 [LOW] CWE-863 GHSA-4phw-6824-6cfp: An issue was discovered in OpenStack Keystone 14 through 26 before 26
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.
GHSA
OpenStack Keystone: Restricted application credentials can create EC2 credentials
ghsa·2026-04-10
CVE-2026-33551 [LOW] CWE-863 OpenStack Keystone: Restricted application credentials can create EC2 credentials
OpenStack Keystone: Restricted application credentials can create EC2 credentials
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-33551 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.5
CVE-2026-33551 [LOW] CVE-2026-33551 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33551 :
Linux Debian vulnerability analysis and mitigation
[Restricted application credentials can create EC2 credentials]
Source : NVD
Published April 8, 2026
CNA Score N/A
Affected Technologies
Linux Debian
Echo
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
keystone
Sources
NVD
Debian 11, 12, 13, 14 No Fix Added at: Apr 09, 2026
Echo No Fix Added at: Apr 09, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Debian vulnerabilities:
CVE ID
Severity
Score
Technologies
Component n
Bugzilla
CVE-2026-33551 openstack-keystone: OpenStack Keystone: Privilege escalation through EC2 credential creation
bugzilla·2026-03-25·CVSS 3.5
CVE-2026-33551 [LOW] CVE-2026-33551 openstack-keystone: OpenStack Keystone: Privilege escalation through EC2 credential creation
CVE-2026-33551 openstack-keystone: OpenStack Keystone: Privilege escalation through EC2 credential creation
Maxence Bornecque from Orange Cyberdefense CERT Vulnerability Intelligence Watch Team reported a vulnerability in Keystone's EC2 credential creation endpoint. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.
2026-04-10
Published