Executive brief
OpenStack Keystone's credential management API fails to properly restrict delegated authentication tokens (such as EC2 keys and application credentials) from modifying credentials they should not access. An attacker holding a delegated token can overwrite other users' multi-factor authentication seeds, read sensitive credential data, delete credentials, or move credentials across project boundaries. This affects all Keystone deployments that use delegated authentication methods.
Technical details
The vulnerability is a broken access control issue in the /v3/credentials API endpoints (POST, PATCH, DELETE) that fail to validate whether a token has primary authentication. Delegated tokens (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) bypass credential operation restrictions. The PATCH endpoint checks the pre-image credential's project scope but not the post-image project_id in the request body, allowing a delegated token scoped to project A to move a credential to project B. EC2-derived tokens additionally can read credential blobs, exposing TOTP MFA seeds and other secrets. The root cause is the absence of a primary authentication requirement guard in the patch() and delete() handlers in credentials.py, and incomplete validation in post(). The attack requires only a delegated token (obtainable through compromised EC2 keys or application credentials) and network access to the Keystone API.
Affected products
- OpenStack Keystone before 29.0.3
Timeline
- 2026-07-01: disclosed
- 2026-09-11: advisory
- other: Related bug 2153453 (credential creation via delegated tokens) and bug 2158970 (TOTP modification without MFA re-auth) also cited