GHSA-4phw-6824-6cfp · Severity: low · Ecosystem: pip — OpenStack Keystone: Restricted application credentials can create EC2 credentials
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.
Conclusion & alert: CVE-2026-33551 is rated Exploit Available (50/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.02%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-10 | — | 0.02% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 3.5 | 3.1 | LOW |
|
1.8 | 1.4 | [email protected] |
| 5.3 | 3.1 | MEDIUM |
|
1.6 | 3.6 | [email protected] |
GHSA-4phw-6824-6cfp · Severity: low · Ecosystem: pip — OpenStack Keystone: Restricted application credentials can create EC2 credentials
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-33551 not yet assigned priority: Debian including 1 source packages (keystone), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 3, open 2. | https://security-tracker.debian.org/tracker/CVE-2026-33551 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2026-33551 |
ubuntu
|
medium | CVE-2026-33551 medium priority: Ubuntu including 1 source packages (keystone), 7 status rows across 7 suites (bionic, focal, jammy, noble, questing, upstream, xenial): needs-triage 7. | https://ubuntu.com/security/CVE-2026-33551 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| openstack | keystone | >= 14.0.0, < 26.1.1 | cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* |
| openstack | keystone | 27.0.0 | cpe:2.3:a:openstack:keystone:27.0.0:*:*:*:*:*:*:* |
| openstack | keystone | 28.0.0 | cpe:2.3:a:openstack:keystone:28.0.0:*:*:*:*:*:*:* |
| openstack | keystone | 29.0.0 | cpe:2.3:a:openstack:keystone:29.0.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://bugs.launchpad.net/keystone/+bug/2142138 | Exploit Issue Tracking |
| https://security.openstack.org/ossa/OSSA-2026-005.html | Vendor Advisory Patch |
| http://www.openwall.com/lists/oss-security/2026/04/07/12 | Mailing List Patch Third Party Advisory |