Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-90460

Quick assessment

Affected
OpenStack Keystone
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenStack Keystone 在 29.0.3 之前存在以下问题: 通过委托认证方式(包括 EC2 凭据、应用凭据、OAuth1 访问令牌和信任关系)获取的令牌,并未被阻止通过 API 创建、修改或删除凭据。此外,由 EC2 派生的令牌还可以读取凭据内容(credential blobs),从而可能泄露 TOTP 多因子认证种子(seeds)及其他机密信息。同时, 接口未校验更新后请求中的 ,导致任意委托令牌可以将凭据移至未授权的项目。所有使用委托认证的 Keystone 部署均受此漏洞影响。

CVSS 7.6 · High EPSS 0.34% · P27

Affected Version Matrix 3

VendorProduct Version RangeStatus
OpenStack Keystone 13.0.0< 27.0.3 affected
28.0.0< 28.0.3 affected
29.0.0< 29.0.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90460

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the /v3/credentials API. EC2-derived tokens can additionally read credential blobs, exposing TOTP MFA seeds and other secrets. Also, PATCH /v3/credentials does not validate the requested post-update project_id, allowing any delegated token to move a credential to an unauthorized project. All Keystone deployments using delegated authentication are affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenStack Keystone 13.0.0 ~ 27.0.3 -

II. Public POCs for CVE-2026-90460

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90460

登录查看更多情报信息。

Patches & Fixes for CVE-2026-90460 (1)

Other References for CVE-2026-90460 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-90460

No comments yet


Leave a comment