RHSA-2026:28044HighCVSS 8.0

Red Hat Security Advisory: Red Hat OpenStack Platform 17.1 (openstack-keystone) security update

Published
June 22, 2026
Last Modified
September 21, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2025-65073 — openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via AWS signature validation flaw CVE-2026-33551 — openstack-keystone: OpenStack Keystone: Privilege escalation through EC2 credential creation CVE-2026-43001 — OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation

🎯 Affected products15

  • Red Hat OpenStack Platform 17.1
  • openstack-keystone-1:19.0.2-17.1.20260529190847.54dd95d.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-keystone-1:19.0.2-17.1.20260529190847.54dd95d.el9ost.src as a component of Red Hat OpenStack Platform 17.1
  • openstack-swift-0:2.27.1-17.1.20231004180819.el9ost.src as a component of Red Hat OpenStack Platform 17.1
  • openstack-swift-account-0:2.27.1-17.1.20231004180819.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-swift-container-0:2.27.1-17.1.20231004180819.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-swift-object-0:2.27.1-17.1.20231004180819.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-swift-proxy-0:2.27.1-17.1.20231004180819.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-tempest-1:33.0.0-17.1.20260406141650.1580f6f.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • openstack-tempest-1:33.0.0-17.1.20260406141650.1580f6f.el9ost.src as a component of Red Hat OpenStack Platform 17.1
  • openstack-tempest-all-1:33.0.0-17.1.20260406141650.1580f6f.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • python3-keystone-1:19.0.2-17.1.20260529190847.54dd95d.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • python3-swift-0:2.27.1-17.1.20231004180819.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • python3-tempest-1:33.0.0-17.1.20260406141650.1580f6f.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1
  • python3-tempest-tests-1:33.0.0-17.1.20260406141650.1580f6f.el9ost.noarch as a component of Red Hat OpenStack Platform 17.1

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To reduce exposure, ensure that OpenStack application credentials are created with the most restrictive scope possible, limiting their permissions to only what is essential for their intended function. If EC2 credentials are not actively used within your OpenStack deployment, consider disabling the EC2 credential API endpoint in Keystone to prevent unauthorized creation of cross-project EC2 credentials. Refer to the OpenStack Keystone administration guide for detailed instructions on managing application credential scopes and disabling API endpoints. Any changes to Keystone configuration may require a service restart to take effect.

🔗 References (5)