Linuxsecurity
Critical Vulnerabilities in OpenStack Keystone Affect Multiple Ubuntu Releases
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
OpenStack Keystone has been found to have several critical vulnerabilities affecting Ubuntu versions 22.04 LTS, 24.04 LTS, 25.10, and 26.04 LTS. Notably, CVE-2026-33551 allows authenticated attackers with reader roles to bypass application credential restrictions and create EC2 credentials. Another issue, CVE-2026-40683, enables attackers to authenticate as disabled users due to improper LDAP attribute handling. Additional vulnerabilities include CVE-2026-42998, which allows impersonation of other users, and CVE-2026-42999, which permits arbitrary policy attribute injection. These vulnerabilities were disclosed between April and May 2026, with patches available for affected systems. Administrators are advised to update their systems promptly to mitigate these risks.
Key Points: • OpenStack Keystone vulnerabilities affect multiple Ubuntu LTS versions. • CVE-2026-33551 allows role bypass for EC2 credential creation. • Patches are available; immediate updates are recommended.