An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint.
References
| Link | Resource |
|---|---|
| https://bugs.launchpad.net/keystone/+bug/2149775 | Exploit Issue Tracking Patch Third Party Advisory |
| https://review.opendev.org/c/openstack/keystone/+/985804 | Patch |
| https://security.openstack.org/ossa/OSSA-2026-015.html | Patch Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:39808 | |
| https://access.redhat.com/security/cve/CVE-2026-43001 | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2464305 | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43001.json |
Configurations
Configuration 1 (hide)
|
History
15 Jul 2026, 14:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Jun 2026, 03:19
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-1288 | |
| References |
|
17 Jun 2026, 10:48
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://bugs.launchpad.net/keystone/+bug/2149775 - Exploit, Issue Tracking, Patch, Third Party Advisory | |
| References | () https://security.openstack.org/ossa/OSSA-2026-015.html - Patch, Vendor Advisory |
02 Jun 2026, 15:20
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://bugs.launchpad.net/keystone/+bug/2149775 - Exploit, Issue Tracking, Third Party Advisory, Patch | |
| References | () https://security.openstack.org/ossa/OSSA-2026-015.html - Vendor Advisory, Patch |
28 May 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. | |
| References |
|
04 May 2026, 18:25
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* | |
| First Time |
Openstack keystone
Openstack |
|
| References | () https://bugs.launchpad.net/keystone/+bug/2149775 - Exploit, Issue Tracking | |
| References | () https://review.opendev.org/c/openstack/keystone/+/985804 - Patch |
01 May 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-01 09:16
Updated : 2026-07-15 14:18
NVD link : CVE-2026-43001
Mitre link : CVE-2026-43001
CVE.ORG link : CVE-2026-43001
JSON object : View
Products Affected
openstack
- keystone
