An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity.
Metrics
Affected Vendors & Products
References
History
Thu, 28 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OpenStack Keystone Privilege Escalation via Trust Exploit |
Thu, 28 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity. | |
| First Time appeared |
Openstack
Openstack keystone |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack keystone |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-05-28T00:00:00.000Z
Updated: 2026-05-28T19:41:55.135Z
Reserved: 2026-05-01T00:00:00.000Z
Link: CVE-2026-43000
Updated: 2026-05-28T19:41:43.429Z
Status : Analyzed
Published: 2026-05-28T19:16:37.773
Modified: 2026-06-02T14:38:58.967
Link: CVE-2026-43000
No data.