Red Hat Product Errata RHSA-2026:39808 - Security Advisory Issued: 2026-07-15 Updated: 2026-07-15 RHSA-2026:39808 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat OpenStack Services on OpenShift 18.0 (openstack-keystone) security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for openstack-keystone is now available for Red Hat OpenStack Services on OpenShift 18.0 (Antelope). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Keystone is a Python implementation of the OpenStack ( http://www.openstack.org ) identity service API. Security Fix(es): Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation (CVE-2026-43001) Keystone: OpenStack Keystone: Unauthorized access due to incorrect LDAP user status handling (CVE-2026-40683) OpenStack Keystone: Privilege escalation through EC2 credential creation (CVE-2026-33551) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat OpenStack Services on OpenShift 18.0 x86_64 Fixes BZ - 2451037 - CVE-2026-33551 openstack-keystone: OpenStack Keystone: Privilege escalation through EC2 credential creation BZ - 2458472 - CVE-2026-40683 OpenStack Keystone: OpenStack Keystone: Unauthorized access due to incorrect LDAP user status handling BZ - 2464305 - CVE-2026-43001 OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation CVEs CVE-2026-33551 CVE-2026-40683 CVE-2026-43001 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat OpenStack Services on OpenShift 18.0 SRPM openstack-keystone-23.0.3-18.0.20260610133808.9e3dfb4.el9ost.src.rpm SHA-256: 0664c4a19e6d49d2f2a55bc38bd445346f9a788e0e837946e2ab5ceef4a8c713 x86_64 openstack-keystone-23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch.rpm SHA-256: a8baf3183a783c1c684a8c8580626c0f41790081bda38c4d2c241940ac213ac6 python3-keystone-23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch.rpm SHA-256: 71fd2cf6431bd0bc7741fb795c8ed1542ef06b4d2d955534a838e35bcad611e1 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This Important update for Red Hat OpenStack Services on OpenShift 18.0 addresses three vulnerabilities in openstack-keystone, including CVE-2026-43001 (CVSS 7.9 High), which allows unauthorized cross-project access via improper validation during EC2 credential creation. According to NVD data, openstack-keystone versions 14.0.0 through 26.1.1, 27.0.0, 28.0.0, and 29.0.0 are affected, with fixes available in versions 26.1.1, 27.0.2, 28.0.2, and 29.0.2. The advisory provides updated RPM packages for the RHOSO 18.0 distribution to remediate these issues.