{
  "threat_severity" : "Moderate",
  "public_date" : "2026-05-28T00:00:00Z",
  "bugzilla" : {
    "description" : "openstack-keystone: OpenStack Keystone: User impersonation and unauthorized access via insufficient application credential verification.",
    "id" : "2482825",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2482825"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.9",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-303",
  "details" : [ "An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects.", "A flaw was found in OpenStack Keystone. The application credential authentication plugin fails to verify if the user provided in an authentication request matches the owner of the application credential. This allows a remote attacker to authenticate with their own credentials while impersonating another user, gaining unauthorized access to project-scoped resources and potentially evading audits. The attacker can read the victim's credentials and act as the victim within shared projects." ],
  "statement" : "This MODERATE impersonation vulnerability in Keystone's application credential plugin allows authenticated users to obtain tokens attributed to other users. Exploitation requires high complexity (valid app credentials and shared project context). Impact is limited to the intersection of attacker's app credential roles and victim's actual project roles. Affects versions before 29.0.2.",
  "package_state" : [ {
    "product_name" : "Red Hat OpenStack Platform 13 (Queens)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhosp13/openstack-keystone",
    "cpe" : "cpe:/a:redhat:openstack:13"
  }, {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "fix_state" : "Fix deferred",
    "package_name" : "openstack-keystone",
    "cpe" : "cpe:/a:redhat:openstack:16.2"
  }, {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "fix_state" : "Fix deferred",
    "package_name" : "rhosp-rhel8/openstack-keystone",
    "cpe" : "cpe:/a:redhat:openstack:16.2"
  }, {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Fix deferred",
    "package_name" : "openstack-keystone",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhosp-rhel9/openstack-keystone",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 18.0",
    "fix_state" : "Fix deferred",
    "package_name" : "openstack-keystone",
    "cpe" : "cpe:/a:redhat:openstack:18.0"
  }, {
    "product_name" : "Red Hat OpenStack Platform 18.0",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoso/openstack-keystone-rhel9",
    "cpe" : "cpe:/a:redhat:openstack:18.0"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-42998\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42998\nhttps://bugs.launchpad.net/keystone/+bug/2148477\nhttps://security.openstack.org/ossa/OSSA-2026-015.html" ],
  "name" : "CVE-2026-42998",
  "csaw" : false
}