CVE-2026-43001

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*

History

15 Jul 2026, 14:18

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:39808 -

30 Jun 2026, 03:19

Type Values Removed Values Added
CWE CWE-1288
References
  • () https://access.redhat.com/security/cve/CVE-2026-43001 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2464305 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43001.json -

17 Jun 2026, 10:48

Type Values Removed Values Added
References () https://bugs.launchpad.net/keystone/+bug/2149775 - Exploit, Issue Tracking, Third Party Advisory, Patch () https://bugs.launchpad.net/keystone/+bug/2149775 - Exploit, Issue Tracking, Patch, Third Party Advisory
References () https://security.openstack.org/ossa/OSSA-2026-015.html - Vendor Advisory, Patch () https://security.openstack.org/ossa/OSSA-2026-015.html - Patch, Vendor Advisory

02 Jun 2026, 15:20

Type Values Removed Values Added
References () https://bugs.launchpad.net/keystone/+bug/2149775 - Exploit, Issue Tracking () https://bugs.launchpad.net/keystone/+bug/2149775 - Exploit, Issue Tracking, Third Party Advisory, Patch
References () https://security.openstack.org/ossa/OSSA-2026-015.html - () https://security.openstack.org/ossa/OSSA-2026-015.html - Vendor Advisory, Patch

28 May 2026, 19:16

Type Values Removed Values Added
Summary (en) An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. (en) An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint.
References
  • () https://security.openstack.org/ossa/OSSA-2026-015.html -

04 May 2026, 18:25

Type Values Removed Values Added
CPE cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
First Time Openstack keystone
Openstack
References () https://bugs.launchpad.net/keystone/+bug/2149775 - () https://bugs.launchpad.net/keystone/+bug/2149775 - Exploit, Issue Tracking
References () https://review.opendev.org/c/openstack/keystone/+/985804 - () https://review.opendev.org/c/openstack/keystone/+/985804 - Patch

01 May 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-01 09:16

Updated : 2026-07-15 14:18


NVD link : CVE-2026-43001

Mitre link : CVE-2026-43001

CVE.ORG link : CVE-2026-43001


JSON object : View

Products Affected

openstack

  • keystone
CWE
CWE-863

Incorrect Authorization

CWE-1288

Improper Validation of Consistency within Input