Role Assignment Exposure in OpenStack Keystone by OpenStack Foundation
CVE-2026-80183
7.1HIGH
What is CVE-2026-80183?
In OpenStack Keystone prior to version 29.0.3, an improper access control vulnerability allows authenticated users with the 'reader' role to enumerate all project-scoped role assignments within any domain. By utilizing the GET /v3/role_assignments endpoint with the domain ID as scope.project.id and the parameter include_subtree, users can retrieve detailed information about roles and their assignments, including user and group names associated with each domain. This issue arises from a flaw in handling domain_id checks, potentially leading to unauthorized data exposure and allowing attackers to map out project roles extensively across cloud deployments.
Affected Version(s)
Keystone 16.0.0 < 27.0.3
Keystone 28.0.0 < 28.0.3
Keystone 29.0.0 < 29.0.3
