#1149303 lp-2159643: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds (CVE-2026-pending)

Package:
src:keystone
Source:
src:keystone
Submitter:
Thomas Goirand
Date:
2026-10-09 13:47:04 UTC
Severity:
normal
Tags:
#1149303#5
Date:
2026-09-29 10:02:12 UTC
From:
To:
Copying launchpad.net bug from:
https://bugs.launchpad.net/keystone/+bug/2159643

Tokens obtained via delegated authentication methods (ec2credential,
application_credential) can call PATCH /v3/credentials and DELETE
/v3/credentials/{id} on any credential owned by the same user, regardless of
credential type.

This allows a holder of an ec2 access/secret key pair (or an application
credential) to:

  • Overwrite a TOTP seed (type=totp) — immediately invalidates the user's
    authenticator app and substitutes the attacker's seed, bypassing MFA
  • Read credentials:
    • ec2credential token can Read TOTP seed — full silent MFA compromise (as
      well as any other credential blobs)
    • application_credential token is correctly blocked from GET on individual
      credentials (403), but can still list all ec2 credentials (one API call
      dumps all credentials with their complete secrets)
  • Change the project_id of any ec2 credential — re-scopes the credential to
    any other project the user has roles in, escalating the access the key
    provides. (A holder of an ec2 access/secret key pair can use the token
    obtained from that key to change the project_id of that same credential,
    re-scoping it to any other project the user has roles in.)
  • Delete TOTP, SSH, or other credential types — credential wipe/DoS
  • Create new credentials of any type via POST /v3/credentials (also unblocked
    for ec2credential tokens — see bug 2153453 for the related CREATE gap)

Steps to reproduce (PATCH TOTP seed via ec2credential token):

  1. User creates an ec2 credential and a TOTP credential
  2. Attacker obtains the ec2 access/secret keys (e.g., from a shared server)
  3. Attacker calls POST /v3/ec2tokens (via a service account) to obtain an
     ec2credential token
  4. Attacker calls PATCH /v3/credentials/{totp_cred_id} with the new TOTP seed
     using that token → 200 OK
  5. User's authenticator app is now invalid; attacker controls the MFA seed

Steps to reproduce (project_id scope escalation):

  1. User has ec2 credential scoped to Project A (member), and also has admin
     role in Project B
  2. Attacker obtains the ec2 access/secret
  3. Attacker gets ec2credential token, calls PATCH
     /v3/credentials/{ec2_cred_id} with {"project_id": "<project_B_id>",
     "blob": "..."}
  4. Next ec2tokens call returns a token scoped to Project B with admin role

Root cause:

credentials.py patch() and delete() handlers have no guard against delegated
token methods. post() has a partial guard
(_check_unrestricted_application_credential) that bug 2153453 is extending,
but patch() and delete() have no equivalent. The _validate_blob_update_keys
guard only fires for existing ec2-type credentials and only validates blob key
stability, not the token method.

Proposed fix:

Add a _require_primary_auth guard to POST, PATCH, and DELETE in credentials.py
(and users.py OS-EC2 endpoint) that blocks any token whose methods list
contains no primary authentication method:

  _PRIMARY_METHODS = frozenset({'password', 'totp', 'mapped', 'token'})
  def _require_primary_auth_for_credential_write(token):
      if not _PRIMARY_METHODS.intersection(token.methods):
          raise exception.ForbiddenAction(
              action=_("Modifying credentials requires primary "
                       "authentication (password, totp, or mapped).")
          )

This covers ec2credential, application_credential, oauth1, and trust tokens by
default, and any future delegated method without needing per-type guards. It
also handles third-party custom credential types.

Note: This is the tip of the iceberg. EC2-derived tokens and application
credential tokens produce fully-privileged project-scoped Keystone tokens
usable against any OpenStack service API. Nova's keypair API (POST/DELETE
/v2/{project_id}/os-keypairs) has the same structural exposure — a stolen ec2
key can add attacker-controlled SSH keypairs to a project. This behavior is
undocumented -- one might assume that EC2 tokens work only on EC2/S3 APIs.
Nova and other services do not introspect token methods; enforcement there
would require a broader cross-project effort.

Note2: Type is a free-form string, no validation or whitelist. Any auth
plugin, integration, or third-party service can store credentials under
custom types. So any restrictions might interfere with legitimate, custom
usage.

Severity: High
Affects: All Keystone versions with ec2credentials enabled
Related: bug 2153453 (credential creation via delegated tokens), bug 2158970
(Adding/removing TOTP credentials requires no MFA re-auth)

#1149303#10
Date:
2026-09-29 12:17:38 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/40ae58a630b2cf274971c5755456e91f2e80920f
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#15
Date:
2026-09-29 12:18:12 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/9e47b8967080f38cf66484fea866a9dbaff3b429
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#18
Date:
2026-09-29 12:33:20 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/1d676e1ec150b5611439b7abe234cca74b3a1385
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#21
Date:
2026-09-29 13:06:29 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/3322860de03f4c5b4ab327d2e6f25351ade14aaa
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#24
Date:
2026-09-29 13:40:10 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/c490f55c8aedbc968e908d8f206c1584d68799eb
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#27
Date:
2026-09-29 13:53:30 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/e9afb0589401d6bbb4cf56913db2072c0dc6531b
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#30
Date:
2026-09-29 14:29:41 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/24aa6b68cca86b4b463a7c944f36d7f6324b11da
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#33
Date:
2026-09-29 14:29:42 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/a73e4663460f625de8ec12828b8e3738cf0c104f
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#36
Date:
2026-09-29 15:07:49 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/76a8e111c49f4f36211455ccc8c35bd7ccbfe2a1
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#39
Date:
2026-09-29 15:07:50 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/72cc3300325e7b1e15942f0c4a17d4ed270b9ab5
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#42
Date:
2026-09-29 15:43:00 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/a93a8c3c5c2cd6950599e38a9f5349c624f3c8f2
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#45
Date:
2026-09-29 18:55:49 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/85bbb4c7040c63894e8a7f8f5bc476d817566596
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#48
Date:
2026-09-29 19:13:01 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/5fecf2bc8b997380055a1c46a905bd34a2633132
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#51
Date:
2026-09-29 19:19:57 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/cd8a399a1a15b3f15ea21a868322ed7e8b143581
------------------------------------------------------------------------
* CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303):
    - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#58
Date:
2026-10-06 17:43:04 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/112b6899466c6561aa84fc38a5d10944885cf1db
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#61
Date:
2026-10-06 17:44:11 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/7ac5b82d27fd45cf7a7f37dfccb8f27176c207f2
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#64
Date:
2026-10-06 17:44:18 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/321ff5fec6779ed52961ba706680ba7838ae4531
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#67
Date:
2026-10-06 17:46:00 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/1498872d0da59e74c92b4b42ac35269c7ff8c9e5
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#70
Date:
2026-10-06 17:46:09 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/50c195201478d0cff46b7ea0667ee07973fc749e
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#73
Date:
2026-10-06 17:47:54 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/98e9818252d062c5e7cd3d133f8d39618d6264c4
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#76
Date:
2026-10-06 17:48:00 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/1232f36b5f9d25dcaaa9c49c1da4ae60f4dba7e3
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#79
Date:
2026-10-06 17:48:31 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/1a465a9a3438c87dff0e85ccdd421f675ed3a272
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#82
Date:
2026-10-06 18:07:53 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/6edca0332d93309d1b9ecd2c6a569987c13cb2c4
------------------------------------------------------------------------
CVE-2026-90460: Delegated tokens (like ec2credential,
application_credential, ...) can GET/PATCH/DELETE any credential including
TOTP seeds. Delegation project boundary not enforced on PATCH
/v3/credentials/{id}. Applied upstream patch: "credentials: reject
delegated tokens, restrict PATCH to blob only" (Closes: #1149303,
#1149956):
- CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303

#1149303#85
Date:
2026-10-08 22:28:33 UTC
From:
To:
Hello,

Bug #1149303 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/6f94605929491d13ed73c35cd121f675d7a4d7bb
------------------------------------------------------------------------
CVE-2026-90460: Delegated tokens (like ec2credential,
application_credential, ...) can GET/PATCH/DELETE any credential including
TOTP seeds. Delegation project boundary not enforced on PATCH
/v3/credentials/{id}. Applied upstream patch: "credentials: reject
delegated tokens, restrict PATCH to blob only" (Closes: #1149303,
#1149956):
- CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149303