Description
In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.
Published: 2026-08-25
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Identity and privilege escalation via unauthorized creation of long‑lived credentials and delegations
Action: Immediate Patch
AI Analysis

Impact

A flaw in OpenStack Keystone allows an attacker holding a delegated authentication token—such as an OAuth1 access token, an application credential, or a trust-scoped token—to create new long‑lived credentials or authorize additional delegations that persist beyond the lifetime of the original token. The delegation restrictions that are supposed to block these actions do not consistently apply to all delegated token types, giving an OAuth1‑scoped token the ability to create application credentials or authorise OAuth1 request tokens even when such operations are otherwise forbidden. This bypasses normal authorization controls, enabling an attacker to obtain credentials that permit broader or longer‑lasting access than intended.

Affected Systems

OpenStack Keystone versions earlier than 29.0.3. Any Keystone deployment that permits delegated authentication through OAuth1 access tokens, application credentials, or trust-based authentication is vulnerable.

Risk and Exploitability

The CVSS score of 7.6 categorises this vulnerability as high severity. Although the EPSS score is not provided, the exploitation of this weakness would require only a valid delegated token, which could be obtained through legitimate authentication flows or potentially stolen credentials. The attack vector is network‑based, involving the Keystone API. The vulnerability is not listed in CISA’s KEV catalog; however, the high CVSS score combined with the broad applicability of the affected token types indicates a significant risk to confidentiality and integrity of privileged credentials. Mitigation by applying the stated patch or disabling the affected delegated authentication mechanisms is essential to prevent the creation of unauthorized credentials.

Generated by OpenCVE AI on August 26, 2026 at 01:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenStack Keystone to version 29.0.3 or later to remove the vulnerability.
  • If an upgrade cannot be performed immediately, disable OAuth1 access tokens, application credential usage, or trust‑based delegated tokens in the Keystone configuration.
  • Enforce stricter token scopes and short expirations to limit the impact of any remaining delegated tokens.
  • Implement monitoring to detect unexpected creation of application credentials or OAuth1 request tokens.

Generated by OpenCVE AI on August 26, 2026 at 01:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4767-1 keystone security update
Debian DSA Debian DSA DSA-6480-1 keystone security update
History

Wed, 26 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Delegated Tokens Enable Unauthorized Creation of Credentials in Keystone keystone: keystone: Delegated token scope restrictions not consistently enforced across trust, OAuth1, and application credential endpoints
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

threat_severity

Important


Wed, 26 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Delegated Tokens Enable Unauthorized Creation of Credentials in Keystone

Tue, 25 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Description In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.
First Time appeared Openstack
Openstack keystone
Weaknesses CWE-863
CPEs cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
Vendors & Products Openstack
Openstack keystone
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openstack Keystone
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-26T14:38:22.666Z

Reserved: 2026-08-25T21:19:09.801Z

Link: CVE-2026-80182

cve-icon Vulnrichment

Updated: 2026-08-26T14:38:19.716Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-25T22:17:07.067

Modified: 2026-09-09T16:03:22.897

Link: CVE-2026-80182

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-25T15:00:00Z

Links: CVE-2026-80182 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T02:00:04Z

Weaknesses