← Späť na vyhľadávanie CVE

CVE-2026-43000

OpenStack Keystone

Popis

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim-s identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim-s actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim-s admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim-s identity.

CVSS 6EPSS 0.328%Riziko 0.62
Zobraziť zdroj
Zverejnené
2026-05-28 19:16:37
Dotknuté verzie
<29.0.2
Typ
Core software
Posledná úprava
2026-07-23 12:18:03
Vektor
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L