CVE-2026-80182

Source
https://cve.org/CVERecord?id=CVE-2026-80182
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80182.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80182
Downstream
Published
2026-08-25T21:19:10Z
Modified
2026-09-11T03:30:42Z
Severity
  • 7.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.

Database specific
{
    "cna_assigner": "mitre",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80182.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "13.0.0"
                },
                {
                    "fixed": "27.0.3"
                },
                {
                    "introduced": "28.0.0"
                },
                {
                    "fixed": "28.0.3"
                },
                {
                    "introduced": "29.0.0"
                },
                {
                    "fixed": "29.0.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "13.0.0"
                },
                {
                    "fixed": "27.0.3"
                },
                {
                    "introduced": "28.0.0"
                },
                {
                    "fixed": "28.0.3"
                },
                {
                    "introduced": "29.0.0"
                },
                {
                    "fixed": "29.0.3"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "29.0.3"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / opendev.org/openstack/keystone

Affected ranges

Type
GIT
Repo
https://opendev.org/openstack/keystone
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
07c1aafdf20db6d6d7c0d3e15074bc02e2f1d2aa
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "OAuth1"
        }
    ],
    "source": "DESCRIPTION"
}

Affected versions

2011.*
2011.3
Other
essex-4
essex-rc1
folsom-1
folsom-2
folsom-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80182.json"