Vulnerability record · CVE-2026-33551 · published 10 April 2026
CVE-2026-33551: Openstack keystone incorrect authorization vulnerability
Openstack · Keystone
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.
Description
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugs.launchpad.net/keystone/+bug/2142138 | ExploitIssue Tracking |
| https://security.openstack.org/ossa/OSSA-2026-005.html | PatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/04/07/12 | Mailing ListPatchThird Party Advisory |
| https://bugs.launchpad.net/keystone/+bug/2142138 | ExploitIssue Tracking |
Track CVE-2026-33551 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-33551), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.