CVE-2026-22797
Unknown
Unknown - Not Provided
OAuth 2.0 Header Injection in OpenStack Keystone Middleware Enables Privilege Escalation
Publication date: 2026-01-19
Last updated on: 2026-01-19
Assigner: MITRE
Description
Description
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| openstack | keystonemiddleware | From 10.5 (inc) to 10.7.2 (exc) |
| openstack | keystonemiddleware | From 10.8 (inc) to 10.9.1 (exc) |
| openstack | keystonemiddleware | From 10.10 (inc) to 10.12.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-290 | This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks. |