CVE-2026-33551 Details
Description
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.
A vulnerability exists in OpenStack Keystone versions 14 through 26 prior to 26.1.1, as well as in versions 27.0.0, 28.0.0, and 29.0.0. The issue allows restricted application credentials to create EC2 credentials. An authenticated user with only a reader role can use a restricted application credential to call the EC2 credential creation API, thereby obtaining an EC2/S3 credential that includes full access to the user's S3 permissions. This effectively bypasses the role restrictions of the application credential. The vulnerability affects deployments that use restricted application credentials with the EC2/S3 compatibility API (swift3/s3api).
Users can upgrade to OpenStack Keystone versions 26.1.1, 27.0.1, 28.0.1, or 29.0.1, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugs.launchpad.net/keystone/+bug/2142138 | CISA-ADP | ExploitIssue Tracking |
| http://www.openwall.com/lists/oss-security/2026/04/07/12 | CVE | Mailing ListPatchThird Party Advisory |
| https://bugs.launchpad.net/keystone/+bug/2142138 | [email protected] | ExploitIssue Tracking |
| https://security.openstack.org/ossa/OSSA-2026-005.html | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openstack keystone | >= 14.0.0, < 26.1.1 27.0.0 28.0.0 29.0.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| Apr 10, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | CVE Modified | CVE |
| Apr 10, 2026 | New CVE Received | [email protected] |