CVE-2026-43001

Aliases:GHSA-hhq2-3832-xxcvPYSEC-2026-602DEBIAN-CVE-2026-43001CGA-2jm6-8mc8-37jwCGA-4r87-47wf-9m44CGA-6vpj-ggc8-xhhfCGA-7464-wj8q-g7p8CGA-92f9-gcpw-58wmCGA-9mh7-w7g8-6656CGA-f493-fmf8-r67mCGA-hp5x-wfmx-v64wCGA-j448-w48p-w84vCGA-m43c-g4mr-cvw2CGA-pcpr-xqch-pp5wCGA-q7g3-cvmj-rmpxCGA-r7cq-36v3-743xCGA-r9qp-8m5p-p28qCGA-v452-4hwq-3jxvCGA-x5c3-m2xf-4949CGA-xcwp-wgq6-9jcm
Advisory lineage Upstream: 0 Downstream: 5
Modified
Published: 01 May 2026, 00:00
Last modified:14 Aug 2026, 12:04

Vulnerability Summary

Overall Risk (default)
medium
42/100
CVSS Score
8 HIGH
v3.1 (nvd)
EPSS Score
0.47% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

01 May 2026, 00:00
Published
Vulnerability first disclosed
14 Aug 2026, 12:04
Last Modified
Vulnerability information updated

Description

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint.

CVSS Metrics

  • v3.1HIGHScore: 7.9CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
  • v3.1HIGHScore: 8CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.47% Percentile: 40%

Techniques & Countermeasures

  • CWE-863Incorrect Authorization

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

  • CWE-1288Improper Validation of Consistency within Input

    The product receives a complex input with multiple elements or fields that must be consistent with each other, but it does not validate or incorrectly validates that the input is actually consistent.

Affected Systems

  • chainguardopenstack-keystone-2025.1

    < 27.0.1-r0

  • chainguardopenstack-keystone-2025.1-fips

    < 27.0.1_git20260601-r3

  • chainguardopenstack-keystone-2025.2

    < 28.0.1-r0

  • chainguardopenstack-keystone-2025.2-fips

    < 28.0.1_git20260603-r0 | < 28.0.1_git20260610-r1 | < 28.0.1_git20260610-r0 | < 28.0.1_git20260608-r1

  • chainguardopenstack-keystone-2026.1

    < 29.0.1-r0

  • debiankeystone

    < 2:18.1.0-1+deb11u3 | < 2:22.0.2-0+deb12u3 | < 2:27.0.0-3+deb13u4 | < 2:29.0.1-2

  • openstackkeystone

    ≥ 13, ≤ 29 | ≥ 13.0.0, ≤ 19.0.0 | ≥ 14.0.0, < 27.0.2 | ≥ 28.0.0, < 28.0.2 | ≥ 29.0.0, < 29.0.2

  • PyPIkeystone

    ≥ 29.0.0, < 29.0.2 | ≥ 13.0.0, ≤ 29.0.1

References (13)