Fedora Account System
Red Hat Associate
Red Hat Customer
Maxence Bornecque from Orange Cyberdefense CERT Vulnerability Intelligence Watch Team reported a vulnerability in Keystone's EC2 credential creation endpoint. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.
This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 for RHEL 9 Via RHSA-2026:28044 https://access.redhat.com/errata/RHSA-2026:28044
This issue has been addressed in the following products: Red Hat OpenStack Services on OpenShift 18.0 Via RHSA-2026:39808 https://access.redhat.com/errata/RHSA-2026:39808
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2026:54757 https://access.redhat.com/errata/RHSA-2026:54757