← Vulnerability feed

Vulnerability record · CVE-2026-33551 · published 10 April 2026

CVE-2026-33551: Openstack keystone incorrect authorization vulnerability

Openstack · Keystone

An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.

5.3 CVSS 3.1 Medium EPSS 0.33% · top 76.8% CWE-863 · Incorrect authorization
5.3CVSS 3.1 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-33551 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-42998Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user …EPSS 0.40%8.8CVE-2026-42999Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON re…EPSS 0.42%8.8CVE-2026-43000Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker wi…EPSS 0.43%8.8CVE-2020-12689Openstack keystone improper privilege management vulnerabilityAn issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application crede…EPSS 1.6%8.8CVE-2020-12690Openstack keystone insufficient session expiration vulnerabilityAn issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. T…EPSS 1.9%8.8CVE-2020-12691Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a pro…EPSS 4.9%8.8CVE-2019-19687Openstack keystone insufficiently protected credentials vulnerabilityOpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any c…EPSS 1.8%8.1CVE-2026-44394Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2026-33551), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.