CVE-2026-22797
An OpenStack keystonemiddleware vulnerability allows attackers to forge authentication headers and gain higher privileges or impersonate users.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
OpenStack keystonemiddleware versions 10.5‑10.7 (before 10.7.2), 10.8, 10.9 (before 10.9.1), and 10.10‑10.12 (before 10.12.1) that use the external_oauth2_token middleware.
Real-world impact
An attacker who can authenticate can send forged headers such as X-Is-Admin-Project, X-Roles, or X-User-Id to elevate privileges or impersonate other users, potentially accessing sensitive data or performing actions as another user.
Why this severity
The CVSS score of 9.9 reflects that the vulnerability is network‑reachable, requires low effort, and gives attackers high confidentiality and integrity impact, while availability impact is low.
What to do about it
- 01Upgrade OpenStack keystonemiddleware to a patched release (10.7.2, 10.8, 10.9.1, or 10.12.1 or later).
- 02Restart the keystonemiddleware service to apply the update.
NVD description
Timeline
- Jan 19, 2026 · Jan 19, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 16d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Aug 3, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- launchpad.net/bugs/2129018
- openwall.com/lists/oss-security/2026/01/…
- openwall.com/lists/oss-security/2026/01/…
- openwall.com/lists/oss-security/2026/01/…
- openwall.com/lists/oss-security/2026/01/…
- openwall.com/lists/oss-security/2026/01/…
- access.redhat.com/errata/RHSA-2026:3402
- access.redhat.com/errata/RHSA-2026:3855
- access.redhat.com/errata/RHSA-2026:4434
- access.redhat.com/errata/RHSA-2026:5133
- access.redhat.com/errata/RHSA-2026:5907
- access.redhat.com/security/cve/CVE-2026-22797
- bugzilla.redhat.com/show_bug.cgi
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2…