Token Scope Bypass in OpenStack Keystone Impacting Delegated Authentication
CVE-2026-80184
7.6HIGH
What is CVE-2026-80184?
In OpenStack Keystone prior to 29.0.3, a vulnerability exists where tokens acquired via delegated authentication methods such as OAuth1 access tokens, application credentials, and trusts can be improperly reused. These tokens can escape their defined project boundaries when reauthenticated, leading to unintended access. Specifically, when an application credential token is presented without an explicit scope, Keystone generates a new token scoped to the owner's default project instead of the intended project. This poses significant risks for any Keystone deployments that allow delegated authentication protocols.
Affected Version(s)
Keystone 13.0.0 < 27.0.3
Keystone 28.0.0 < 28.0.3
Keystone 29.0.0 < 29.0.3
