CVE-2026-43001: Openstack Keystone
High severity, CVSS 8.0. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint.
Affected products
- Openstack Keystone: from 14.0.0, before 27.0.2 (fixed in 27.0.2); from 28.0.0, before 28.0.2 (fixed in 28.0.2); from 29.0.0, before 29.0.2 (fixed in 29.0.2)
Published 2026-05-01. Last modified 2026-08-14.