CVE-2026-80183

HIGH CVSS 4.0: 7.1 EPSS 0.23%
Updated Aug 27, 2026
Openstack
Parameter Value
CVSS 7.1 (HIGH)
Affected Versions 16.0.0 — 29.0.3
Fixed In 27.0.3
Type CWE-843 (Type Confusion)
Vendor Openstack
Public PoC No

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved.

The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in  list_role_assignments_for_tree.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products 3

Configuration From (including) Up to (excluding)
Openstack Keystone
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
16.0.0 27.0.3
Openstack Keystone
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
28.0.0 28.0.3
Openstack Keystone
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
29.0.0 29.0.3