---
id: CVE-2026-43001
title: >-
  OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due
  to improper validation in EC2 credential creation (CVE-2026-4…
summary: >-
  A flaw was found in OpenStack Keystone. An attacker holding an unrestricted
  application credential could exploit a vulnerability in the POST
  /v3/credentials endpoint where the caller-supplied project_id for an EC2-type
  credential was not v…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-1288
vendor: Red Hat
product: Red Hat OpenStack Platform 17.1
affected:
  - openstack_platform 16.2
  - openstack_platform 17.1
  - openstack_services_on_openshift 18.0
patched:
  - openstack_platform 16.2
  - openstack_platform 17.1
  - openstack_services_on_openshift 18.0
published: '2026-05-01'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T12:21:11+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43001.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43001.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-43001'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2464305'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-43001'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-43001'
  - url: 'https://bugs.launchpad.net/keystone/+bug/2149775'
  - url: 'https://review.opendev.org/c/openstack/keystone/+/985804'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54757'
  - url: 'https://access.redhat.com/errata/RHSA-2026:28044'
  - url: 'https://access.redhat.com/errata/RHSA-2026:39808'
  - url: 'https://review.opendev.org/c/openstack/keystone'
  - url: 'https://security.openstack.org/ossa/OSSA-2026-015.html'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00587
epssPercentile: 0.45775
aliases:
  - GHSA-hhq2-3832-xxcv
  - PYSEC-2026-602
ecosystem: pip
scores:
  vendor: 8
  osv: 7.9
ingestedAt: '2026-07-08T18:25:50.249Z'
---

## Overview

A flaw was found in OpenStack Keystone. An attacker holding an unrestricted application credential could exploit a vulnerability in the POST /v3/credentials endpoint where the caller-supplied project_id for an EC2-type credential was not validated against the project of the authenticating application credential. This allows the attacker to create an EC2 credential targeting a different project. Subsequently, a /v3/ec2tokens exchange would issue a Keystone token scoped to the targeted project, enabling unauthorized cross-project access and lateral movement within the credential owner's role footprint.

## Vendor advisories

- **RHSA-2026:54757** · Red Hat · fixed in: Red Hat OpenStack Platform 16.2 · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54757)
- **RHSA-2026:28044** · Red Hat · fixed in: Red Hat OpenStack Platform 17.1 · released 2026-06-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:28044)
- **RHSA-2026:39808** · Red Hat · fixed in: Red Hat OpenStack Services on OpenShift 18.0 · released 2026-07-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:39808)

**OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation** — rated Important by Red Hat. Released 2026-05-01, updated 2026-09-21.

Fixed:

- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Services on OpenShift 18.0

Not affected:

- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 13 (Queens)
- Red Hat OpenStack Platform 18.0

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:54757
For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:28044
For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:39808

Workarounds / mitigations:

- To reduce exposure, ensure that OpenStack application credentials are created with the most restrictive scope possible, limiting their permissions to only what is essential for their intended function. If EC2 credentials are not actively used within your OpenStack deployment, consider disabling the EC2 credential API endpoint in Keystone to prevent unauthorized creation of cross-project EC2 credentials. Refer to the OpenStack Keystone administration guide for detailed instructions on managing a…

## Package advisory (CVE-2026-43001)

Affected packages:

- `keystone >= 13.0.0, <= 29.0.1`

Source: https://osv.dev/vulnerability/GHSA-hhq2-3832-xxcv
