RHSA-2026:39808HighCVSS 8.0

Red Hat Security Advisory: Red Hat OpenStack Services on OpenShift 18.0 (openstack-keystone) security update

Published
July 15, 2026
Last Modified
September 21, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-33551 — openstack-keystone: OpenStack Keystone: Privilege escalation through EC2 credential creation CVE-2026-40683 — OpenStack Keystone: OpenStack Keystone: Unauthorized access due to incorrect LDAP user status handling CVE-2026-43001 — OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation

🎯 Affected products4

  • Red Hat OpenStack Services on OpenShift 18.0
  • openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch as a component of Red Hat OpenStack Services on OpenShift 18.0
  • openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.src as a component of Red Hat OpenStack Services on OpenShift 18.0
  • python3-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch as a component of Red Hat OpenStack Services on OpenShift 18.0

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, configure OpenStack Keystone to correctly interpret the LDAP user enabled attribute. Set the `user_enabled_invert` option to `True` in the `keystone.conf` file. Example: ```ini [ldap] user_enabled_invert = True ``` After modifying the configuration, restart the Keystone service for the changes to take effect. This may temporarily disrupt authentication services. Additionally the user should start using an LDAP attribute with inverted semantics (such as nsAccountLock) to match the same semantics of the keystone side. Workaround: To reduce exposure, ensure that OpenStack application credentials are created with the most restrictive scope possible, limiting their permissions to only what is essential for their intended function. If EC2 credentials are not actively used within your OpenStack deployment, consider disabling the EC2 credential API endpoint in Keystone to prevent unauthorized creation of cross-project EC2 credentials. Refer to the OpenStack Keystone administration guide for detailed instructions on managing application credential scopes and disabling API endpoints. Any changes to Keystone configuration may require a service restart to take effect.

🔗 References (6)