OAuth1 Delegation Vulnerability in OpenStack Keystone
CVE-2026-80182

7.6HIGH

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-80182?

In OpenStack Keystone versions before 29.0.3, a critical vulnerability exists that allows tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication to create long-lived credentials or authorize delegations that persist independently of their originating credentials. The delegation restrictions intended to block such operations were not uniformly applied across all token types, meaning that OAuth1-scoped tokens could bypass restrictions that would normally apply to other delegated token types. This poses significant security risks to deployments utilizing delegated authentication with OAuth1 within Keystone.

Affected Version(s)

Keystone 13.0.0 < 27.0.3

Keystone 28.0.0 < 28.0.3

Keystone 29.0.0 < 29.0.3

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.