A security notice published on September 30, 2026 describes three OpenStack Keystone vulnerabilities involving delegated tokens and role assignment queries.
Notice USN-8854-1, published on September 30, 2026, reports three flaws in OpenStack Keystone. CVE-2026-80182 concerns inconsistent restrictions on delegated authentication tokens: an authenticated attacker could create credentials or delegations lasting longer than the delegated token. CVE-2026-80183 concerns incorrect handling of certain role assignment queries, which could expose sensitive information; the notice limits its impact to Ubuntu 20.04 LTS, 22.04 LTS, 24.04 LTS, and 26.04 LTS.
The third flaw, CVE-2026-80184, concerns inadequate restrictions on reauthentication using delegated tokens and could let an authenticated attacker exceed the intended project scope. To assess affected systems and remediation guidance, consult the original USN-8854-1 notice through Ubuntu’s official security channels and verify the versions and technical details there. If using AI to study or apply the notice, avoid submitting tokens, credentials, or internal data; use sanitized material and check conclusions against the official source.