CVE-2026-22797: CWE-290 Authentication Bypass by Spoofing in OpenStack keystonemiddleware
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.
AI Analysis
Technical Summary
CVE-2026-22797 is a privilege escalation vulnerability in the external_oauth2_token middleware component of OpenStack keystonemiddleware, which is part of Red Hat OpenShift Container Platform. The flaw arises because the middleware does not correctly sanitize incoming authentication headers, enabling an authenticated attacker to send forged identity headers (e.g., X-Is-Admin-Project, X-Roles, X-User-Id). Exploiting this flaw can allow attackers to escalate privileges or impersonate other users. Red Hat has rated this vulnerability as Important and assigned a CVSS v3 base score of 9.9, indicating high severity. The fix is included in OpenShift Container Platform 4.21.4, which contains updated container images and packages. Users are advised to upgrade to this release to mitigate the vulnerability.
Potential Impact
An authenticated attacker can exploit this vulnerability to escalate privileges or impersonate other users by sending forged authentication headers. This compromises access control and authentication mechanisms, potentially allowing unauthorized access to sensitive resources within Red Hat OpenShift Container Platform deployments that use the affected middleware. The vulnerability affects confidentiality, integrity, and to a lesser extent availability, with a high impact on confidentiality and integrity.
Mitigation Recommendations
Red Hat has released OpenShift Container Platform version 4.21.4 containing fixes for this vulnerability. Users should upgrade to version 4.21.4 or later as soon as possible using the official upgrade documentation. The vendor advisory confirms the availability of an official fix. No alternative mitigations are specified. Users should follow Red Hat's upgrade instructions to fully apply the update and remediate the issue.
CVE-2026-22797: CWE-290 Authentication Bypass by Spoofing in OpenStack keystonemiddleware
Description
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.
CVSS v3.1
Score 9.9critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-22797 is a privilege escalation vulnerability in the external_oauth2_token middleware component of OpenStack keystonemiddleware, which is part of Red Hat OpenShift Container Platform. The flaw arises because the middleware does not correctly sanitize incoming authentication headers, enabling an authenticated attacker to send forged identity headers (e.g., X-Is-Admin-Project, X-Roles, X-User-Id). Exploiting this flaw can allow attackers to escalate privileges or impersonate other users. Red Hat has rated this vulnerability as Important and assigned a CVSS v3 base score of 9.9, indicating high severity. The fix is included in OpenShift Container Platform 4.21.4, which contains updated container images and packages. Users are advised to upgrade to this release to mitigate the vulnerability.
Potential Impact
An authenticated attacker can exploit this vulnerability to escalate privileges or impersonate other users by sending forged authentication headers. This compromises access control and authentication mechanisms, potentially allowing unauthorized access to sensitive resources within Red Hat OpenShift Container Platform deployments that use the affected middleware. The vulnerability affects confidentiality, integrity, and to a lesser extent availability, with a high impact on confidentiality and integrity.
Mitigation Recommendations
Red Hat has released OpenShift Container Platform version 4.21.4 containing fixes for this vulnerability. Users should upgrade to version 4.21.4 or later as soon as possible using the official upgrade documentation. The vendor advisory confirms the availability of an official fix. No alternative mitigations are specified. Users should follow Red Hat's upgrade instructions to fully apply the update and remediate the issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:3402
- Cve Count
- 1
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a3de72f4853345fc1128279
Added to database: 06/26/2026, 02:42:55 UTC
Last enriched: 08/16/2026, 17:20:34 UTC
Last updated: 09/14/2026, 10:01:29 UTC
Views: 376
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.