UNKNOWN OpenStack
CVE-2026-42998
OSSA-2026-015: Multiple credential delegation and authorization bypass vulnerabilities in Keystone
Boris Bobrov from SAP SE reported that an authenticated attacker can inject RBAC policy targets via the JSON request body, bypassing authorization on any policy-protected endpoint to read credential secrets, create credentials for arbitrary users, and escalate to cloud admin (CVE-2026-42999). Application credential authentication does not verify the caller owns the credential, enabling user impersonation within a shared project (CVE-2026-42998). This impersonation can be chained with trusts to e
Affected Products
- Keystone: >=14.0.0 <27.0.2, >=28.0.0 <28.0.2, >=29.0.0 <29.0.2
- CVE-2026-42998
- CVE-2026-42999
- CVE-2026-43000
References
- https://security.openstack.org/ossa/OSSA-2026-015.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-42998
- https://nvd.nist.gov/vuln/detail/CVE-2026-42999
This unknown severity vulnerability was published on 2026-05-28 via OpenStack. Affected: Keystone: >=14.0.0 <27.0.2, >=28.0.0 <28.0.2, >=29.0.0 <29.0.2, CVE-2026-42998, CVE-2026-42999 and 1 more.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.