{"id":"CVE-2026-43001","title":"OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation (CVE-2026-4…","summary":"A flaw was found in OpenStack Keystone. An attacker holding an unrestricted application credential could exploit a vulnerability in the POST /v3/credentials endpoint where the caller-supplied project_id for an EC2-type credential was not v…","severity":"high","cvss":8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-1288","vendor":"Red Hat","product":"Red Hat OpenStack Platform 17.1","affected":["openstack_platform 16.2","openstack_platform 17.1","openstack_services_on_openshift 18.0"],"patched":["openstack_platform 16.2","openstack_platform 17.1","openstack_services_on_openshift 18.0"],"published":"2026-05-01","updated":"2026-09-21","sourceUpdated":"2026-09-21T12:21:11+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43001.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43001.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-43001"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2464305"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-43001"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43001"},{"url":"https://bugs.launchpad.net/keystone/+bug/2149775"},{"url":"https://review.opendev.org/c/openstack/keystone/+/985804"},{"url":"https://access.redhat.com/errata/RHSA-2026:54757"},{"url":"https://access.redhat.com/errata/RHSA-2026:28044"},{"url":"https://access.redhat.com/errata/RHSA-2026:39808"},{"url":"https://review.opendev.org/c/openstack/keystone"},{"url":"https://security.openstack.org/ossa/OSSA-2026-015.html"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00587,"epssPercentile":0.45703,"aliases":["GHSA-hhq2-3832-xxcv","PYSEC-2026-602"],"ecosystem":"pip","scores":{"vendor":8,"osv":7.9},"ingestedAt":"2026-07-08T18:25:50.249Z","slug":"CVE-2026-43001","body":"## Overview\n\nA flaw was found in OpenStack Keystone. An attacker holding an unrestricted application credential could exploit a vulnerability in the POST /v3/credentials endpoint where the caller-supplied project_id for an EC2-type credential was not validated against the project of the authenticating application credential. This allows the attacker to create an EC2 credential targeting a different project. Subsequently, a /v3/ec2tokens exchange would issue a Keystone token scoped to the targeted project, enabling unauthorized cross-project access and lateral movement within the credential owner's role footprint.\n\n## Vendor advisories\n\n- **RHSA-2026:54757** · Red Hat · fixed in: Red Hat OpenStack Platform 16.2 · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54757)\n- **RHSA-2026:28044** · Red Hat · fixed in: Red Hat OpenStack Platform 17.1 · released 2026-06-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:28044)\n- **RHSA-2026:39808** · Red Hat · fixed in: Red Hat OpenStack Services on OpenShift 18.0 · released 2026-07-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:39808)\n\n**OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation** — rated Important by Red Hat. Released 2026-05-01, updated 2026-09-21.\n\nFixed:\n\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n- Red Hat OpenStack Services on OpenShift 18.0\n\nNot affected:\n\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 13 (Queens)\n- Red Hat OpenStack Platform 18.0\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:54757\nFor details on how to apply this update, which includes the changes\ndescribed in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:28044\nFor details on how to apply this update, which includes the changes\ndescribed in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:39808\n\nWorkarounds / mitigations:\n\n- To reduce exposure, ensure that OpenStack application credentials are created with the most restrictive scope possible, limiting their permissions to only what is essential for their intended function. If EC2 credentials are not actively used within your OpenStack deployment, consider disabling the EC2 credential API endpoint in Keystone to prevent unauthorized creation of cross-project EC2 credentials. Refer to the OpenStack Keystone administration guide for detailed instructions on managing a…\n\n## Package advisory (CVE-2026-43001)\n\nAffected packages:\n\n- `keystone >= 13.0.0, <= 29.0.1`\n\nSource: https://osv.dev/vulnerability/GHSA-hhq2-3832-xxcv","depth":"twilight","depthScore":44,"depthScoreParts":{"impact":44,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208458,"id":"CVE-2026-43001","ts":1790005706634,"field":"cvss","old":"7.9","new":"8"}]}