Cross-Project Credential Vulnerability in OpenStack Keystone
CVE-2026-43001
7.9HIGH
What is CVE-2026-43001?
A security flaw in OpenStack Keystone versions 13 through 29 allows attackers with unrestricted application credentials for one project to create EC2 credentials intended for a different project. This vulnerability occurs due to insufficient validation of the caller-supplied project_id during the credentials request process. This enables an attacker to obtain a Keystone token scoped to a different project, facilitating unauthorized access and lateral movement across projects within the owner’s role permissions.
Affected Version(s)
Keystone 13 <= 29
