CVE-2026-42998
published 2026-05-28CVE-2026-42998: An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.30%
21.9th percentile
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | keystone | >= 14.0.0 < 27.0.2 | 27.0.2 |
| openstack | keystone | >= 28.0.0 < 28.0.2 | 28.0.2 |
| openstack | keystone | >= 29.0.0 < 29.0.2 | 29.0.2 |
| rhoso | openstack-keystone-rhel9 | — | — |
| rhosp-rhel8 | openstack-keystone | — | — |
| rhosp-rhel9 | openstack-keystone | — | — |
| rhosp13 | openstack-keystone | — | — |
| ubuntu | keystone | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8f8m-wrvr-wcvf: An issue was discovered in OpenStack Keystone before 29
ghsa_unreviewed·2026-05-28
CVE-2026-42998 [MEDIUM] CWE-863 GHSA-8f8m-wrvr-wcvf: An issue was discovered in OpenStack Keystone before 29
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects.
VulDB
OpenStack Keystone up to 27.0.1/28.0.1/29.0.1 Authentication Plugin authorization
vuldb·2026-05-28·CVSS 6.0
CVE-2026-42998 [MEDIUM] OpenStack Keystone up to 27.0.1/28.0.1/29.0.1 Authentication Plugin authorization
A vulnerability, which was classified as problematic, has been found in OpenStack Keystone up to 27.0.1/28.0.1/29.0.1. Affected is an unknown function of the component Authentication Plugin Handler. This manipulation causes incorrect authorization.
This vulnerability is handled as CVE-2026-42998. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2026-06-16·CVSS 5.3
CVE-2026-44394 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Several security issues were fixed in OpenStack Keystone.
It was discovered that OpenStack Keystone allowed restricted application
credentials to create EC2 credentials. An authenticated attacker with only
a reader role could possibly use this issue to bypass the role restrictions
imposed on the application credential. (CVE-2026-33551)
It was discovered that the OpenStack Keystone LDAP identity backend did
not correctly convert the user enabled attribute to a boolean value.
An attacker could possibly use this issue to authenticate as a user disabled
in LDAP. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
and Ubuntu 25.10. (CVE-2026-40683)
It was discovered that OpenStack Keystone's application credential
authentication pl
Red Hat
openstack-keystone: OpenStack Keystone: User impersonation and unauthorized access via insufficient application credential verification.
vendor_redhat·2026-05-28·CVSS 8.8
CVE-2026-42998 [HIGH] CWE-303 openstack-keystone: OpenStack Keystone: User impersonation and unauthorized access via insufficient application credential verification.
openstack-keystone: OpenStack Keystone: User impersonation and unauthorized access via insufficient application credential verification.
A flaw was found in OpenStack Keystone. The application credential authentication plugin fails to verify if the user provided in an authentication request matches the owner of the application credential. This allows a remote attacker to authenticate with their own credentials while impersonating another user, gaining unauthorized access to project-scoped resources and potentially evading audits. The attacker can read the victim's credentials and act as the victim within shared projects.
Statement: This MODERATE impersonation vulnerability in Keystone's application credential plugin allows authenticated users to obtain tokens attributed to other users. E
No detection rules found.
No public exploits indexed.
2026-05-28
Published