High [CVE-2026-2035364] Delegated token scope restrictions not consistently enforced across trust, OAuth1, and application credential endpoints
This high-severity Red Hat Linux advisory covers CVE-2026-2035364 affecting Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A flaw was found in OpenStack Keystone where delegation boundary enforcement is incomplete across trust, application credential, and OAuth1 authorization endpoints.
Tokens obtained via delegated authentication methods, such as OAuth1 access tokens or custom Keystone authentication plugins, can perform operations beyond their intended scope because endpoint guards only recognized specific delegation types rather than using a comprehensive allowlist.
This allows creating trusts that delegate roles beyond the token's authorized scope, creating persistent application credentials, and authorizing new OAuth1 delegations.
These derived credentials persist independently and survive revocation of the original credential, enabling an attacker with a compromised narrow-scope credential to escalate to the user's full privileges and maintain persistent access. Exploitation requires a valid delegated credential, which a project member can typically create.
The Keystone API is network-accessible. Red Hat OpenStack Platform 16.2, 17.1, and 18.0 (including RHOSO) ship the openstack-keystone package and contain the incomplete trust, application credential, and OAuth1 guards.
After the update, custom Keystone authentication plugins cannot mint new delegations unless the operator adds them to [auth] additional_primary_auth_methods.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Mitigation checklist
- There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If OAuth1 authentication is not required, remove 'oauth1' from the [auth] methods configuration option in keystone.conf. 2. Restrict access to the Keystone API to trusted networks via firewall rules. 3. Review and rotate application credentials, trusts, and OAuth1 access tokens after a suspected compromise.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.