Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80183

Quick assessment

Affected
OpenStack Keystone
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 OpenStack Keystone 29.0.3 版本之前,任何在任意项目中拥有 角色的已认证用户,都可以通过在 GET 端点传递域 ID 作为 参数并启用 ,来列出任何域下的所有项目级角色分配。由于该域的项目记录的 为 ,导致策略检查中 的校验对任意调用者均能通过。当启用 时,响应会披露所有涉及的用户、组、项目和角色的名称及其所属主域 ID。字面量 域 ID 对任何通过 创建的部署都有效。攻击者可以从响应中收集域 ID,并重复执行查询,从而映射整个云环境中的角色分配情况。该漏洞的根本原因在于 中对 的错误使

CVSS 7.1 · High

Possible ATT&CK Techniques 1 AI

T1204 · User Execution
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80183

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in  list_role_assignments_for_tree.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenStack Keystone 16.0.0 ~ 27.0.3 -

II. Public POCs for CVE-2026-80183

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80183

登录查看更多情报信息。

Vendor Pages for CVE-2026-80183 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-80183

No comments yet


Leave a comment