CVE-2026-43001 Details
Description
An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint.
A vulnerability in OpenStack Keystone versions 13 through 29 allows for cross-project credential escalation. The issue arises because the application credential's project_id is not properly validated when creating EC2-type credentials. This flaw enables an attacker with an unrestricted application credential in one project to create an EC2 credential for another project. By exchanging this EC2 credential for a Keystone token scoped to the second project, the attacker can access resources within that project's role footprint.
The vulnerability has been fixed in the OpenStack Keystone master branch and will be backported to the stable/2026.1 branch. Users should update to the latest version in these branches.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:39808 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:54757 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-43001 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2464305 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43001.json | redhat-SADP | |
| https://bugs.launchpad.net/keystone/+bug/2149775 | [email protected] | ExploitIssue TrackingPatchThird Party Advisory |
| https://review.opendev.org/c/openstack/keystone/+/985804 | [email protected] | Patch |
| https://security.openstack.org/ossa/OSSA-2026-015.html | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1288 | Improper Validation of Consistency within Input | redhat-SADP |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openstack keystone | >= 14.0.0, < 27.0.2 >= 28.0.0, < 28.0.2 >= 29.0.0, < 29.0.2 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 14, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 2, 2026 | Modified Analysis | [email protected] |
| May 28, 2026 | CVE Modified | [email protected] |
| May 4, 2026 | Initial Analysis | [email protected] |
| May 1, 2026 | New CVE Received | [email protected] |