CVE-2026-42998: CWE-863 Incorrect Authorization in OpenStack Keystone
A vulnerability in OpenStack Keystone before version 29.0.2 allows an attacker to impersonate another user by authenticating with their own application credential but specifying a different user's name and domain. This results in Keystone issuing a token attributed to the victim user with project-scoped roles that combine the attacker's and victim's permissions. The flaw enables audit evasion, unauthorized reading of victim credentials, and acting as the victim within shared projects.
AI Analysis
Technical Summary
CVE-2026-42998 is an incorrect authorization vulnerability (CWE-863) in OpenStack Keystone's application credential authentication plugin prior to version 29.0.2. The plugin fails to verify that the user in the authentication request matches the owner of the application credential. An attacker can supply their own credential ID and secret but specify a different user's identity, causing Keystone to issue a token attributed to the victim user. The token is project-scoped with roles intersecting the attacker's application credential roles and the victim's actual project roles, allowing impersonation and unauthorized actions within shared projects.
Potential Impact
The vulnerability allows an attacker to impersonate another user within OpenStack Keystone, enabling audit evasion and unauthorized access to the victim's credentials and project-scoped permissions. This can lead to unauthorized actions performed under the victim's identity, potentially compromising confidentiality, integrity, and availability within affected projects.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary mitigation has been documented in the provided data. Users should monitor OpenStack Keystone advisories for updates and apply any forthcoming patches promptly.
CVE-2026-42998: CWE-863 Incorrect Authorization in OpenStack Keystone
Description
A vulnerability in OpenStack Keystone before version 29.0.2 allows an attacker to impersonate another user by authenticating with their own application credential but specifying a different user's name and domain. This results in Keystone issuing a token attributed to the victim user with project-scoped roles that combine the attacker's and victim's permissions. The flaw enables audit evasion, unauthorized reading of victim credentials, and acting as the victim within shared projects.
CVSS v3.1
Score 6.0medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-42998 is an incorrect authorization vulnerability (CWE-863) in OpenStack Keystone's application credential authentication plugin prior to version 29.0.2. The plugin fails to verify that the user in the authentication request matches the owner of the application credential. An attacker can supply their own credential ID and secret but specify a different user's identity, causing Keystone to issue a token attributed to the victim user. The token is project-scoped with roles intersecting the attacker's application credential roles and the victim's actual project roles, allowing impersonation and unauthorized actions within shared projects.
Potential Impact
The vulnerability allows an attacker to impersonate another user within OpenStack Keystone, enabling audit evasion and unauthorized access to the victim's credentials and project-scoped permissions. This can lead to unauthorized actions performed under the victim's identity, potentially compromising confidentiality, integrity, and availability within affected projects.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary mitigation has been documented in the provided data. Users should monitor OpenStack Keystone advisories for updates and apply any forthcoming patches promptly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-05-01T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a188e05e29bf47b501d67b5
Added to database: 05/28/2026, 18:48:37 UTC
Last enriched: 07/02/2026, 23:17:21 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.