Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43000

Опубликовано: 28 мая 2026
Источник: redhat
CVSS3: 8.4
EPSS Низкий

Описание

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity.

A flaw was found in OpenStack Keystone. An attacker with a member role on a project can escalate their privileges to an administrator role. This is achieved by combining an application credential impersonation vulnerability with the misuse of Keystone trusts. The system incorrectly validates delegated roles against the victim's actual database roles instead of the requesting token, allowing the attacker to create a trust that grants them the victim's administrative privileges. This trust can then be used to maintain persistent access.

Отчет

This IMPORTANT privilege escalation in Keystone allows project members to gain admin access by chaining application credential impersonation with trust exploitation. High complexity is required (multiple vulnerability chain). The scope is changed as the attacker gains persistent admin access affecting other users. Impact is high to confidentiality and integrity. Affects versions before 29.0.2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-keystoneAffected
Red Hat OpenStack Platform 16.2openstack-keystoneAffected
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-keystoneAffected
Red Hat OpenStack Platform 17.1openstack-keystoneAffected
Red Hat OpenStack Platform 17.1rhosp-rhel9/openstack-keystoneAffected
Red Hat OpenStack Platform 18.0openstack-keystoneAffected
Red Hat OpenStack Platform 18.0rhoso/openstack-keystone-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2482826keystone: OpenStack Keystone: Privilege escalation via chained application credential impersonation and trust misuse

EPSS

Процентиль: 25%
0.00328
Низкий

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 6
ubuntu
2 месяца назад

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity.

CVSS3: 6
nvd
2 месяца назад

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity.

CVSS3: 6
debian
2 месяца назад

An issue was discovered in OpenStack Keystone before 29.0.2. When comb ...

CVSS3: 6
github
2 месяца назад

OpenStack Keystone has an Incorrect Authorization issue

EPSS

Процентиль: 25%
0.00328
Низкий

8.4 High

CVSS3