CVE-2026-33551

unknown
Published 2026-04-10 ยท Modified 2026-04-10
CVSS v3
โ€”
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
โ€”

Description

An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.

Predictions

Exploit likelihood
30%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2026-33551 NameCVE-2026-33551 DescriptionAn issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the fullโ€ฆ

CVE-2026-33551

NameCVE-2026-33551
DescriptionAn issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4611-1
Debian Bugs1133118

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
keystone (PTS)bullseye2:18.0.0-3+deb11u1vulnerable
bullseye (security)2:18.1.0-1+deb11u3fixed
bookworm, bookworm (security)2:22.0.2-0+deb12u1vulnerable
trixie, trixie (security)2:27.0.0-3+deb13u1vulnerable
sid, forky2:29.0.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
keystonesourcebullseye2:18.1.0-1+deb11u3DLA-4611-1
keystonesource(unstable)2:29.0.0-21133118

Notes

[trixie] - keystone <no-dsa> (Minor issue)
[bookworm] - keystone <no-dsa> (Minor issue)
https://launchpad.net/bugs/2142138
https://www.openwall.com/lists/oss-security/2026/04/07/12

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[trixie] - keystone <no-dsa> (Minor issue)[bookworm] - keystone <no-dsa> (Minor issue)https://launchpad.net/bugs/2142138https://www.openwall.com/lists/oss-security/2026/04/07/12

OS impact

debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected โ€”
sid Fixed 2:29.0.0-2
forky Fixed 2:29.0.0-2
bullseye Fixed 2:18.1.0-1+deb11u3
bookworm Affected โ€”

Package impact

EcosystemPackageVulnerableFixed
python PyPIkeystone>=14.0.0,<26.1.126.1.1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.