- Package:
- src:keystone
- Source:
- src:keystone
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-10-09 13:47:04 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for keystone. CVE-2026-90460[0]: | An issue was discovered in OpenStack Keystone before 29.0.3. Tokens | obtained via delegated authentication methods (EC2 credentials, | application credentials, OAuth1 access tokens, and trusts) are not | blocked from creating, modifying, or deleting credentials via the | /v3/credentials API. EC2-derived tokens can additionally read | credential blobs, exposing TOTP MFA seeds and other secrets. Also, | PATCH /v3/credentials does not validate the requested post-update | project_id, allowing any delegated token to move a credential to an | unauthorized project. All Keystone deployments using delegated | authentication are affected. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-90460 https://www.cve.org/CVERecord?id=CVE-2026-90460 [1] https://bugs.launchpad.net/keystone/+bug/2159643 [2] https://bugs.launchpad.net/keystone/+bug/2158931 [3] https://review.opendev.org/c/openstack/keystone/+/1002330 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1149956 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/112b6899466c6561aa84fc38a5d10944885cf1db ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149956
Hello, Bug #1149956 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/7ac5b82d27fd45cf7a7f37dfccb8f27176c207f2 ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149956
Hello, Bug #1149956 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/321ff5fec6779ed52961ba706680ba7838ae4531 ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149956
Hello, Bug #1149956 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/1498872d0da59e74c92b4b42ac35269c7ff8c9e5 ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149956
Hello, Bug #1149956 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/50c195201478d0cff46b7ea0667ee07973fc749e ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149956
Hello, Bug #1149956 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/98e9818252d062c5e7cd3d133f8d39618d6264c4 ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149956
Hello, Bug #1149956 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/1232f36b5f9d25dcaaa9c49c1da4ae60f4dba7e3 ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149956
Hello, Bug #1149956 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/1a465a9a3438c87dff0e85ccdd421f675ed3a272 ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149956