CVE-2026-43001Disclosure(openstack / keystone)

LOWCVSS 8.0 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863CWE-1288

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • keystone

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
keystone

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-01: 3Technical Details · 2026-05-01: 205-01
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-43001 Cross-Project Lateral Movement in OpenStack Keystone 13 Through 29 via EC2 Credentials https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43001

    Post summary

    The post simply announces CVE-2026-43001 with a link for more information, offering no concrete details about exploitation, patches, or proof of concept.

    0000046
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-43001 An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matc… https://www.cve.org/CVERecord?id=CVE-2026-43001 ----- Traducción: CVE-2026-43001 Se … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-43001, a validation bypass in OpenStack Keystone’s EC2 credential handling, providing technical details but no evidence of exploitation, PoC, or patch.

    0000022
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43001 An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matc… https://www.cve.org/CVERecord?id=CVE-2026-43001

    Post summary

    The note announces CVE‑2026‑43001, noting an OpenStack Keystone project_id validation flaw, but offers no PoC, exploit, patch, or evidence of active attacks.

    00000149
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenstackkeystone---

Explore more