Impact
The vulnerability exists in OpenStack Keystone versions before 29.0.3 and represents a CWE-863 weakness: tokens obtained via delegated authentication methods—such as EC2 credentials, application credentials, OAuth1 access tokens, and trusts—are not blocked from creating, modifying, or deleting credentials via the /v3/credentials API. EC2‑derived tokens can also read credential blobs, exposing TOTP MFA seeds and other secrets. Additionally, PATCH /v3/credentials does not validate the requested post-update _project_id_, allowing any delegated token to move a credential to an unauthorized project. This allows a delegated token to effectively privilege‑escalate and compromise credentials across the system.
Affected Systems
All OpenStack Keystone deployments using delegated authentication before version 29.0.3 are affected. This includes any environment that relies on EC2, application credentials, OAuth1, or trust mechanisms within Keystone.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity. Although the EPSS score is < 1%, the exploitation path does not require complex prerequisites and can be performed by an attacker with a delegated token. The vulnerability is not listed in CISA KEV, but the potential to read MFA seeds and move credentials raises serious confidentiality and integrity concerns. Based on the description, it is inferred that an attacker with a delegated token can fully alter credential management, leading to unauthorized access across the system.
OpenCVE Enrichment