CVE-2026-40683Disclosure

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as enabled by Keystone, allowing them to authenticate and perform actions. All deployments using the LDAP identity backend without user_enabled_invert=True or user_enabled_emulation are affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-15); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-15: 2Mentions · 2026-06-17: 1Technical Details · 2026-04-15: 2Technical Details · 2026-06-17: 104-1506-17
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-152
Disclosure2
2026-06-171
Disclosure1
Full discourse3 posts
  • ThreatCluster@threatcluster
    Disclosure

    Ubuntu reported four OpenStack Keystone flaws, including CVE-2026-33551 and CVE-2026-40683, affecting Ubuntu 22.04, 24.04, 25.10 and 26.04 and allowing role bypass, disabled-user logins and user impersonation. https://threatcluster.io/cluster/critical-vulnerabilities-in-openstack-keystone-affect-multip-1d521921

    Post summary

    Ubuntu announced four OpenStack Keystone vulnerabilities, including CVE‑2026‑33551 and CVE‑2026‑40683, that permit role bypass, disabled‑user logins, and user impersonation on several Ubuntu releases.

    0000060
    356 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40683 In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration opt… https://www.cve.org/CVERecord?id=CVE-2026-40683 ----- Traducción: CVE-2026-40683 En … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑40683, describing an LDAP boolean conversion bug in OpenStack Keystone, without providing any PoC, exploit, patch, or evidence of active exploitation.

    00000175
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40683 In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration opt… https://www.cve.org/CVERecord?id=CVE-2026-40683

    Post summary

    CVE-2026-40683 discloses that OpenStack Keystone versions prior to 28.0.1 have an LDAP backend flaw where the user enabled attribute is not converted to a boolean, potentially impacting authentication behavior.

    00000212
    57.2K followersView on X

Explore more