OAuth1 Delegation Vulnerability in OpenStack Keystone
CVE-2026-80182
7.6HIGH
What is CVE-2026-80182?
In OpenStack Keystone versions before 29.0.3, a critical vulnerability exists that allows tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication to create long-lived credentials or authorize delegations that persist independently of their originating credentials. The delegation restrictions intended to block such operations were not uniformly applied across all token types, meaning that OAuth1-scoped tokens could bypass restrictions that would normally apply to other delegated token types. This poses significant security risks to deployments utilizing delegated authentication with OAuth1 within Keystone.
Affected Version(s)
Keystone 13.0.0 < 27.0.3
Keystone 28.0.0 < 28.0.3
Keystone 29.0.0 < 29.0.3
