---
id: CVE-2026-22797
title: >-
  An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7
  before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before
  10.12.1
summary: >-
  An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7
  before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before
  10.12.1. The external_oauth2_token middleware fails to sanitize incoming
  authentication …
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L'
cwe:
  - CWE-290
vendor: OpenStack
product: keystonemiddleware
affected:
  - keystonemiddleware >= 10.5.0 < 10.7.2
  - keystonemiddleware >= 10.8.0 < 10.9.1
  - keystonemiddleware >= 10.10.0 < 10.12.1
patched:
  - openshift_container_platform 4.17
  - openshift_container_platform 4.18
  - openshift_container_platform 4.19
  - openshift_container_platform 4.21
  - openshift_container_platform 4.2
published: '2026-01-19'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:17:43.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-22797'
references:
  - url: 'https://launchpad.net/bugs/2129018'
    label: cve@mitre.org
  - url: 'https://www.openwall.com/lists/oss-security/2026/01/16/9'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/01/15/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/01/16/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/01/16/3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2026/01/16/9'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2026:3402'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:3855'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:4434'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:5133'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:5907'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-22797'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2430879'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22797.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-22797'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-22797'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-01-20T17:27:57.832462Z'
epss: 0.0066
epssPercentile: 0.49769
ingestedAt: '2026-06-30T13:26:50.511Z'
---

## Overview

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:5907** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2026-04-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:5907)
- **RHSA-2026:5133** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2026-03-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:5133)
- **RHSA-2026:4434** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2026-03-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:4434)
- **RHSA-2026:3402** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.21 · released 2026-03-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:3402)
- **RHSA-2026:3855** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.2 · released 2026-03-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:3855)
