#1149956 keystone: CVE-2026-90460

Package:
src:keystone
Source:
src:keystone
Submitter:
Salvatore Bonaccorso
Date:
2026-10-09 13:47:04 UTC
Severity:
normal
Tags:
#1149956#5
Date:
2026-10-04 19:00:49 UTC
From:
To:
Hi,

The following vulnerability was published for keystone.

CVE-2026-90460[0]:
| An issue was discovered in OpenStack Keystone before 29.0.3. Tokens
| obtained via delegated authentication methods (EC2 credentials,
| application credentials, OAuth1 access tokens, and trusts) are not
| blocked from creating, modifying, or deleting credentials via the
| /v3/credentials API. EC2-derived tokens can additionally read
| credential blobs, exposing TOTP MFA seeds and other secrets. Also,
| PATCH /v3/credentials does not validate the requested post-update
| project_id, allowing any delegated token to move a credential to an
| unauthorized project. All Keystone deployments using delegated
| authentication are affected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-90460
https://www.cve.org/CVERecord?id=CVE-2026-90460
[1] https://bugs.launchpad.net/keystone/+bug/2159643
[2] https://bugs.launchpad.net/keystone/+bug/2158931
[3] https://review.opendev.org/c/openstack/keystone/+/1002330

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1149956#8
Date:
2026-10-06 17:43:04 UTC
From:
To:
Hello,

Bug #1149956 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/112b6899466c6561aa84fc38a5d10944885cf1db
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149956

#1149956#13
Date:
2026-10-06 17:44:11 UTC
From:
To:
Hello,

Bug #1149956 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/7ac5b82d27fd45cf7a7f37dfccb8f27176c207f2
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149956

#1149956#16
Date:
2026-10-06 17:44:18 UTC
From:
To:
Hello,

Bug #1149956 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/321ff5fec6779ed52961ba706680ba7838ae4531
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149956

#1149956#19
Date:
2026-10-06 17:46:00 UTC
From:
To:
Hello,

Bug #1149956 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/1498872d0da59e74c92b4b42ac35269c7ff8c9e5
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149956

#1149956#22
Date:
2026-10-06 17:46:09 UTC
From:
To:
Hello,

Bug #1149956 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/50c195201478d0cff46b7ea0667ee07973fc749e
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149956

#1149956#25
Date:
2026-10-06 17:47:54 UTC
From:
To:
Hello,

Bug #1149956 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/98e9818252d062c5e7cd3d133f8d39618d6264c4
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149956

#1149956#28
Date:
2026-10-06 17:48:00 UTC
From:
To:
Hello,

Bug #1149956 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/1232f36b5f9d25dcaaa9c49c1da4ae60f4dba7e3
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149956

#1149956#31
Date:
2026-10-06 17:48:31 UTC
From:
To:
Hello,

Bug #1149956 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/1a465a9a3438c87dff0e85ccdd421f675ed3a272
------------------------------------------------------------------------
* CVE-2026-90460: Delegated tokens (like ec2credential,
    application_credential, ...) can GET/PATCH/DELETE any credential including
    TOTP seeds. Delegation project boundary not enforced on PATCH
    /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015.
    Applied upstream patch: "credentials: reject delegated tokens, restrict
    PATCH to blob only" (Closes: #1149303, #1149956):
    - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch
  * OSSN-0109: identity, credentials: require MFA re-verification for
    sensitive actions:
    - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
      (Closes: #1149305)
    - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch
      (Closes: #1149304)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149956