Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-80182

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.

A flaw was found in OpenStack Keystone where delegation boundary enforcement is incomplete across trust, application credential, and OAuth1 authorization endpoints. Tokens obtained via delegated authentication methods, such as OAuth1 access tokens or custom Keystone authentication plugins, can perform operations beyond their intended scope because endpoint guards only recognized specific delegation types rather than using a comprehensive allowlist. This allows creating trusts that delegate roles beyond the token's authorized scope, creating persistent application credentials, and authorizing new OAuth1 delegations. These derived credentials persist independently and survive revocation of the original credential, enabling an attacker with a compromised narrow-scope credential to escalate to the user's full privileges and maintain persistent access.

Отчет

This vulnerability is rated as Important because an authenticated user with a limited-scope delegated credential, such as an OAuth1 access token or application credential, can escalate to the underlying user's full role set and create persistent trusts or application credentials that survive revocation of the original credential. Exploitation requires a valid delegated credential, which a project member can typically create. The Keystone API is network-accessible. Red Hat OpenStack Platform 16.2, 17.1, and 18.0 (including RHOSO) ship the openstack-keystone package and contain the incomplete trust, application credential, and OAuth1 guards. After the update, custom Keystone authentication plugins cannot mint new delegations unless the operator adds them to [auth] additional_primary_auth_methods. Without that setting, Horizon project switching can break for those logins. A separately identified weakness in EC2 credential authentication is outside the scope of this advisory's comprehensive fix and is being documented by upstream as residual exposure. Client libraries such as python-keystoneclient, python-keystoneauth1, and python-keystonemiddleware do not contain the vulnerable Keystone server code and are not affected.

Меры по смягчению последствий

There is no complete mitigation for this vulnerability. The following measures can reduce risk:

  1. If OAuth1 authentication is not required, remove 'oauth1' from the [auth] methods configuration option in keystone.conf.
  2. Restrict access to the Keystone API to trusted networks via firewall rules.
  3. Review and rotate application credentials, trusts, and OAuth1 access tokens after a suspected compromise.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2openstack-keystoneAffected
Red Hat OpenStack Platform 17.1openstack-keystoneAffected
Red Hat OpenStack Platform 18.0openstack-keystoneAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2517801keystone: keystone: Delegated token scope restrictions not consistently enforced across trust, OAuth1, and application credential endpoints

EPSS

Процентиль: 42%
0.00505
Низкий

8.1 High

CVSS3

Связанные уязвимости

ubuntu
22 дня назад

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.

nvd
22 дня назад

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.

debian
22 дня назад

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access ...

github
22 дня назад

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.

EPSS

Процентиль: 42%
0.00505
Низкий

8.1 High

CVSS3

Уязвимость CVE-2026-80182