CVE-2026-43001

Aliases:GHSA-hhq2-3832-xxcvPYSEC-2026-602
Advisory lineage Upstream: 0 Downstream: 4
Analyzed
Published: 01 May 2026, 00:00
Last modified:15 Jul 2026, 13:48

Vulnerability Summary

Overall Risk (default)
medium
42/100
CVSS Score
8 HIGH
v3.1 (nvd)
EPSS Score
0.45% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

01 May 2026, 00:00
Published
Vulnerability first disclosed
15 Jul 2026, 13:48
Last Modified
Vulnerability information updated

Description

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint.

CVSS Metrics

  • v3.1HIGHScore: 7.9CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
  • v3.1HIGHScore: 8CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.45% Percentile: 36%

Techniques & Countermeasures

  • CWE-863Incorrect Authorization

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

  • CWE-1288Improper Validation of Consistency within Input

    The product receives a complex input with multiple elements or fields that must be consistent with each other, but it does not validate or incorrectly validates that the input is actually consistent.

Affected Systems

  • openstackkeystone

    ≥ 13, ≤ 29 | ≥ 13.0.0, ≤ 19.0.0 | ≥ 14.0.0, < 27.0.2 | ≥ 28.0.0, < 28.0.2 | ≥ 29.0.0, < 29.0.2

  • PyPIkeystone

    ≥ 13.0.0, ≤ 29.0.1 | ≥ 29.0.0, < 29.0.2

References (10)