O

Openstack Security Vulnerabilities (CVE)

Explore vulnerabilities and security advisories affecting Openstack products.

5 known CVE vulnerabilities tracked

Critical
0
High
0
Medium
4
Low
1
None
0

Vulnerabilities By Year

Products Affected

All Openstack CVEs

CVE-2026-44394
6.0 medium

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped au

Keystone May 28, 2026
CVE-2026-43000
6.0 medium

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token car

Keystone May 28, 2026
CVE-2026-42999
6.0 medium

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set fr

Keystone May 28, 2026
CVE-2026-42998
6.0 medium

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credent

Keystone May 28, 2026
CVE-2026-33551
3.5 low

An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role ma

Keystone Apr 10, 2026