USN-8854-1: OpenStack Keystone vulnerabilities
Ubuntu patches OpenStack Keystone flaws that can extend delegated tokens and leak role data.
Ubuntu Security Notice USN-8854-1 covers OpenStack Keystone vulnerabilities. CVE-2026-80182, found by Grzegorz Grasza, can let an authenticated attacker create credentials or delegations that outlast a delegated authentication token. CVE-2026-80183 involves incorrect role-assignment queries that may expose sensitive information on Ubuntu 20.04, 22.04, 24.04, and 26.04 LTS. Tim Shephard also reported a reauthentication restriction issue, but that portion of the notice is truncated.
- CVE-2026-80182 lets authenticated attackers create credentials that outlast delegated tokens.
- CVE-2026-80183 may expose role-assignment data on Ubuntu 20.04 through 26.04 LTS.
- A reauthentication restriction flaw is cited, but the notice text is truncated.
- Ubuntu published USN-8854-1; exploitation is not reported.
Vulnerabilities mentionedAll →
- CVE-2026-801827.6<1%In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new…published
- CVE-2026-801837.1<1%In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain…
Grzegorz Grasza discovered that OpenStack Keystone did not consistently enforce restrictions for delegated authentication tokens. An authenticated attacker could possibly use this issue to create credentials or delegations that outlasted the delegated token. (CVE-2026-80182) It was discovered that OpenStack Keystone incorrectly handled role assignment queries under certain circumstances. An authenticated attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-80183) Tim Shephard discovered that OpenStack Keystone did not properly restrict reauthentication using…
This source does not provide full text. Read it at ubuntu.com.