In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts)… (CVE-2026-80184)
Description
OpenStack Keystone versions prior to 29.0.3 contain a vulnerability where tokens obtained through delegated authentication mechanisms such as OAuth1 access tokens, application credentials, or trusts can be used to bypass intended project scope restrictions. Specifically, when an application credential token without explicit scope is used, Keystone issues a new token scoped to the credential owner's default project instead of the intended project, allowing privilege escalation across project boundaries. This affects all Keystone deployments that allow delegated authentication via these mechanisms.
CVSS v4.0
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In OpenStack Keystone before version 29.0.3, a flaw exists in the token-method authentication path that allows tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) to be reauthenticated in a way that escapes their intended project scope. When an application credential token is presented without an explicit scope, Keystone incorrectly issues a new token scoped to the credential owner's default project rather than the project for which the credential was originally issued. This behavior bypasses project boundary restrictions and can lead to unauthorized access within the OpenStack environment. The vulnerability is tracked as CVE-2026-80184 and is categorized under CWE-863 (Incorrect Authorization).
Potential Impact
An attacker with delegated authentication tokens can escalate privileges by obtaining tokens scoped to projects they should not have access to, potentially accessing resources outside their authorized project boundaries. This undermines project-level access controls in OpenStack Keystone, leading to unauthorized resource access within affected deployments.
Mitigation Recommendations
A fix is available in OpenStack Keystone version 29.0.3 that addresses this scope bypass issue. Users should upgrade to version 29.0.3 or later to remediate this vulnerability. Until patched, deployments should carefully review and restrict delegated authentication mechanisms to minimize exposure. Patch status is not explicitly confirmed in the provided data, but the version boundary indicates remediation in 29.0.3.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-x764-fvmq-4x2r
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-80184"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8efff1acd9273b4908c9e7
Added to database: 08/26/2026, 15:02:09 UTC
Last enriched: 09/09/2026, 17:37:47 UTC
Last updated: 10/10/2026, 18:48:23 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.