CVE-2026-80183: CWE-843 Access of Resource Using Incompatible Type ('Type Confusion') in OpenStack Keystone
Description
CVE-2026-80183 is a high-severity vulnerability in OpenStack Keystone before version 29.0.3. It allows any authenticated user with the role 'reader' on any project to list all project-scoped role assignments under any domain by exploiting a logic flaw in the domain ID check. This leads to unauthorized disclosure of names and home-domain IDs of users, groups, projects, and roles across the cloud deployment. The issue arises from misuse of a null domain_id value in the role assignment listing function, enabling attackers to map role assignments cloud-wide.
CVSS v4.0
Score 7.1high
Affected software
OpenStack
Keystone
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in OpenStack Keystone (CVE-2026-80183) involves a type confusion (CWE-843) where an authenticated user with the 'reader' role on any project can query the GET /v3/role_assignments endpoint with a crafted domain ID as scope.project.id and include_subtree parameter. Due to the domain's project record having domain_id=null, the policy domain_id check incorrectly passes, allowing the user to list every project-scoped role assignment under any domain. Using include_names reveals detailed identity information. The literal 'default' domain ID can be used against deployments created with keystone-manage bootstrap. The root cause is misuse of None in the list_role_assignments_for_tree function. The vulnerability affects versions 16.0.0, 28.0.0, and 29.0.0 of Keystone. No official patch or remediation level is currently documented.
Potential Impact
An attacker with minimal privileges (role:reader on any project) can enumerate all project-scoped role assignments across all domains, disclosing sensitive identity and role information including user, group, project, and role names and domain IDs. This unauthorized information disclosure could aid further attacks or privilege escalation attempts within the cloud environment. The vulnerability does not require elevated privileges beyond 'reader' and does not involve direct code execution or data modification.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict the assignment of the 'reader' role to trusted users only and monitor access to the /v3/role_assignments endpoint. Avoid using the 'default' domain ID in deployments where possible. Follow OpenStack Keystone security advisories for updates and apply patches promptly once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-08-25T21:24:11.765Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8f86fcacd9273b4994709c
Added to database: 08/27/2026, 00:38:20 UTC
Last enriched: 09/09/2026, 14:52:13 UTC
Last updated: 10/10/2026, 18:48:23 UTC
Views: 119
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.