PT-2026-44466 · Openstack · Openstack Keystone

Erichen

·

Published

2026-05-28

·

Updated

2026-06-16

·

CVE-2026-44394

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Keystone versions prior to 29.0.2
Description The federated token rescoping mechanism fails to propagate the original token's expiry to the newly issued token. When a federated user rescopes a token through the 'POST /v3/auth/tokens' endpoint, the handle scoped token() function in the mapped authentication plugin returns response data lacking an expires at value. Consequently, the token provider issues a token with a fresh default Time To Live (TTL). This allows users to maintain indefinite access by repeatedly rescoping tokens before they expire, bypassing configured token lifetime policies. This issue only affects deployments utilizing federated identity, such as SAML2 or OpenID Connect.
Recommendations Update to version 29.0.2 or later.

Fix

DoS

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44394
USN-8433-1

Affected Products

Openstack Keystone