Token Scope Bypass in OpenStack Keystone Impacting Delegated Authentication
CVE-2026-80184

7.6HIGH

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-80184?

In OpenStack Keystone prior to 29.0.3, a vulnerability exists where tokens acquired via delegated authentication methods such as OAuth1 access tokens, application credentials, and trusts can be improperly reused. These tokens can escape their defined project boundaries when reauthenticated, leading to unintended access. Specifically, when an application credential token is presented without an explicit scope, Keystone generates a new token scoped to the owner's default project instead of the intended project. This poses significant risks for any Keystone deployments that allow delegated authentication protocols.

Affected Version(s)

Keystone 13.0.0 < 27.0.3

Keystone 28.0.0 < 28.0.3

Keystone 29.0.0 < 29.0.3

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.