Credential Management Vulnerability in OpenStack Keystone by OpenStack
CVE-2026-90460
7.6HIGH
What is CVE-2026-90460?
A vulnerability in OpenStack Keystone allows tokens obtained through delegated authentication methods to bypass restrictions, enabling unauthorized users to create, modify, or delete credentials via the /v3/credentials API. EC2-derived tokens can also read sensitive information, including TOTP MFA seeds, posing significant security risks. Furthermore, the PATCH request on /v3/credentials fails to validate the project_id, permitting any delegated token to arbitrarily transfer credentials to unauthorized projects. All deployments of Keystone using delegated authentication are at risk.
Affected Version(s)
Keystone 13.0.0 < 27.0.3
Keystone 28.0.0 < 28.0.3
Keystone 29.0.0 < 29.0.3
