Credential Management Vulnerability in OpenStack Keystone by OpenStack
CVE-2026-90460

7.6HIGH

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-90460?

A vulnerability in OpenStack Keystone allows tokens obtained through delegated authentication methods to bypass restrictions, enabling unauthorized users to create, modify, or delete credentials via the /v3/credentials API. EC2-derived tokens can also read sensitive information, including TOTP MFA seeds, posing significant security risks. Furthermore, the PATCH request on /v3/credentials fails to validate the project_id, permitting any delegated token to arbitrarily transfer credentials to unauthorized projects. All deployments of Keystone using delegated authentication are at risk.

Affected Version(s)

Keystone 13.0.0 < 27.0.3

Keystone 28.0.0 < 28.0.3

Keystone 29.0.0 < 29.0.3

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.