Back to overview

CVE-2026-22797

CRITICAL
9.9
CVSS 3.1
Description
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.

Metadata

CVE ID
CVE-2026-22797
State
PUBLISHED
Assigner
mitre
Reserved
2026-01-09 00:00 UTC
Published
2026-01-19 00:00 UTC
Last updated
2026-07-27 12:05 UTC
Primary CWE
CWE-290
CWE-290 Authentication Bypass by Spoofing
Vendor / Product
OpenStack / keystonemiddleware
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
OpenStack keystonemiddleware 10.5.0 < 10.7.2, 10.8.0 < 10.9.1, 10.10.0 < 10.12.1
Weakness (CWE)
CWESourceDescription
CWE-290 cna CWE-290 Authentication Bypass by Spoofing
CWE-290 adp Authentication Bypass by Spoofing
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Back to overview