CVE-2026-80182
Awaiting Analysis Awaiting Analysis - Queue

Keystone OAuth1 Delegation Privilege Escalation

Vulnerability report for CVE-2026-80182, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-09-09

Assigner: MITRE

Description

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-09-09
Generated
2026-09-15
AI Q&A
2026-08-26
EPSS Evaluated
2026-09-13
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openstack keystone to 29.0.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

In OpenStack Keystone before version 29.0.3, tokens obtained through OAuth1 access tokens, application credentials, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist even after the original credential expires. This happens because delegation restrictions were not consistently applied to all token types, allowing unauthorized credential creation or delegation.

Detection Guidance

This vulnerability affects OpenStack Keystone deployments using OAuth1, application credentials, or trusts. To detect it, check for unauthorized creation of long-lived credentials or delegations by reviewing authentication logs for suspicious OAuth1, application credential, or trust operations. Look for tokens that persist beyond their intended scope or create new credentials independently.

Impact Analysis

If you use OpenStack Keystone with OAuth1, application credentials, or trust-scoped authentication, an attacker could exploit this to create persistent credentials or unauthorized delegations. This could lead to unauthorized access to resources, data breaches, or prolonged system compromise even after initial access is revoked.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Persistent unauthorized access could result in data exposure, non-compliance with access control policies, and potential legal or financial penalties.

Mitigation Strategies

Upgrade OpenStack Keystone to version 29.0.3 or later to address the delegation restrictions issue. Review and restrict delegated authentication methods like OAuth1, application credentials, and trusts to prevent unauthorized credential creation or delegation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80182. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart