CVE-2026-43000 Details
Description
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity.
A vulnerability in OpenStack Keystone prior to version 29.0.2 allows for user impersonation and unauthorized privilege escalation. When an attacker with the member role on a project exploits this vulnerability, they can impersonate a user with higher privileges and escalate their own role to admin. This is achieved by injecting a 'user' field into the application credential authentication payload, which Keystone improperly validates. The impersonated token carries the victim's identity, enabling the attacker to create a trust that delegates administrative roles. All actions performed under the escalated privileges are logged under the victim's identity.
Users can update to OpenStack Keystone versions 29.0.2 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-43000 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2482826 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43000.json | redhat-SADP | |
| https://bugs.launchpad.net/keystone/+bug/2148477 | [email protected] | ExploitIssue TrackingPatchThird Party Advisory |
| https://security.openstack.org/ossa/OSSA-2026-015.html | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | redhat-SADP |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openstack keystone | >= 14.0.0, < 27.0.2 >= 28.0.0, < 28.0.2 >= 29.0.0, < 29.0.2 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| May 28, 2026 | New CVE Received | [email protected] |