#VU121642 Improper authorization in Keystone middleware - CVE-2026-22797
Published: January 19, 2026
Keystone middleware
Openstack
Description
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to missing authorization checks in the external_oauth2_token middleware. A remote authenticated user can send forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id and escalate privileges within the application.