← Vulnerability feed

Vulnerability record · CVE-2026-22797 · published 19 January 2026

CVE-2026-22797: Authentication bypass by spoofing vulnerability

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.

9.9 CVSS 3.1 Critical EPSS 0.66% · top 50.5% CWE-290 · Authentication bypass by spoofing Deferred
9.9CVSS 3.1 base score
0.66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
0Affected product versions listed by NVD
14References
10 Sep 2026Last modified by NVD

Description

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

References

Track CVE-2026-22797 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2026-22797), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.