Multiple Keystone vulnerabilities affecting credential delegation and authorization (OSSA-2026-015)
· 4 min read
The vulnerabilities
A series of five related vulnerabilities has been identified in OpenStack Keystone that impact how credentials are delegated and how authorization policies are enforced. These vulnerabilities allow authenticated attackers to bypass security boundaries, impersonate users, and potentially escalate privileges to cloud administrator.
