CVE-2026-43001

high
Published 2026-05-01 · Modified 2026-05-07
CVSS v3
8.5
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
CVSS v2
VIR risk
8.5

Description

OpenStack Keystone has an Incorrect Authorization Issue

Predictions

Exploit likelihood
90%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-43001

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://review.opendev.org/c/openstack/keystone/+/985804

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyaffected
debian debiansidaffected
debian debiantrixieaffected

Package impact

EcosystemPackageVulnerableFixed
python PyPIkeystone>=13.0.0,<=29.0.1
PIPkeystone>= 13.0.0, <= 29.0.1

Application impact

VendorProductVersionsFixed
openstackkeystone{"startIncluding":"13.0.0","endIncluding":"19.0.0"}

References

CWEs

CWE-863

Verify integrity in audit chain (admin only). AS-IS.