CVE-2026-42999
Reported by mitre · Published May 28, 2026
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0).
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| OpenStack | Keystone | 14.0.0, 28.0.0, 29.0.0 |
| Red Hat | Red Hat OpenStack Platform 17.1 | |
| chainguard | openstack-keystone-2025.2 | 0, 0, 0 |
| Red Hat | Red Hat OpenStack Platform 18.0 | |
| Red Hat | Red Hat OpenStack Platform 13 (Queens) | |
| Red Hat | Red Hat OpenStack Platform 16.2 | |
| Red Hat | Red Hat OpenStack Platform 13 (Queens) | |
| Red Hat | Red Hat OpenStack Platform 17.1 | |
| PyPI | keystone | 14.0.0, 29.0.0, 28.0.0 |
| Red Hat | Red Hat OpenStack Platform 17.1 | |
| OpenStack | Keystone | 14.0.0, 29.0.0, 28.0.0 |
| chainguard | openstack-keystone-2025.2-fips | 0, 0, 0 |
| chainguard | openstack-keystone-2026.1 | 0, 0, 0 |
| chainguard | openstack-keystone-2025.1 | 0, 0, 0 |
| Red Hat | Red Hat OpenStack Platform 18.0 | |
| Red Hat | Red Hat OpenStack Platform 18.0 | |
| Red Hat | Red Hat OpenStack Platform 16.2 | |
| openstack | keystone | 29.0.0, 14.0.0, 28.0.0 |
| chainguard | openstack-keystone-2026.1-fips | 0, 0, 0 |
| chainguard | openstack-keystone-2025.1-fips | 0, 0, 0 |
…and 2 more
Timeline
- May 28, 2026 CVE Published
- May 29, 2026 EPSS Score
- May 30, 2026 EPSS Score
- May 31, 2026 EPSS Score
- Jun 1, 2026 EPSS Score
- Jun 1, 2026 Security Advisory
- Jun 5, 2026 EPSS Score
- Jun 8, 2026 Coalition ESS Score
- Jul 23, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 27, 2026 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-42999 advisory
- https://github.com/advisories/GHSA-2r23-2g6v-2m5f advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2026-600.yaml advisory
- RHBZ#2482840 issue
- https://access.redhat.com/security/cve/CVE-2026-42999 advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42999.json advisory