{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42999.json"
      }
    ],
    "title": "openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via arbitrary policy attribute injection",
    "tracking": {
      "current_release_date": "2026-07-23T17:06:51+00:00",
      "generator": {
        "date": "2026-07-23T17:06:51+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.7"
        }
      },
      "id": "CVE-2026-42999",
      "initial_release_date": "2026-05-28T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-05-28T00:00:00+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-22T15:41:21+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-07-23T17:06:51+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenStack Platform 13 (Queens)",
                "product": {
                  "name": "Red Hat OpenStack Platform 13 (Queens)",
                  "product_id": "red_hat_openstack_platform_13_(queens)",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openstack:13"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenStack Platform 13 (Queens)"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenStack Platform 16.2",
                "product": {
                  "name": "Red Hat OpenStack Platform 16.2",
                  "product_id": "red_hat_openstack_platform_16.2",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openstack:16.2"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenStack Platform 16.2"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenStack Platform 17.1",
                "product": {
                  "name": "Red Hat OpenStack Platform 17.1",
                  "product_id": "red_hat_openstack_platform_17.1",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openstack:17.1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenStack Platform 17.1"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenStack Platform 18.0",
                "product": {
                  "name": "Red Hat OpenStack Platform 18.0",
                  "product_id": "red_hat_openstack_platform_18.0",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openstack:18.0"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenStack Platform 18.0"
          },
          {
            "category": "product_version",
            "name": "openstack-keystone.src",
            "product": {
              "name": "openstack-keystone.src",
              "product_id": "openstack-keystone.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/openstack-keystone?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "openstack-keystone",
            "product": {
              "name": "openstack-keystone",
              "product_id": "openstack-keystone",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/openstack-keystone"
              }
            }
          },
          {
            "category": "product_version",
            "name": "python-keystone",
            "product": {
              "name": "python-keystone",
              "product_id": "python-keystone",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/python-keystone"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhosp13/openstack-keystone",
            "product": {
              "name": "rhosp13/openstack-keystone",
              "product_id": "rhosp13/openstack-keystone",
              "product_identification_helper": {
                "purl": "pkg:oci/openstack-keystone?repository_url=registry.redhat.io/rhosp13/openstack-keystone"
              }
            }
          },
          {
            "category": "product_version",
            "name": "python3-keystone",
            "product": {
              "name": "python3-keystone",
              "product_id": "python3-keystone",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/python3-keystone"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhosp-rhel8/openstack-keystone",
            "product": {
              "name": "rhosp-rhel8/openstack-keystone",
              "product_id": "rhosp-rhel8/openstack-keystone",
              "product_identification_helper": {
                "purl": "pkg:oci/openstack-keystone?repository_url=registry.redhat.io/rhosp-rhel8/openstack-keystone"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhosp-rhel9/openstack-keystone",
            "product": {
              "name": "rhosp-rhel9/openstack-keystone",
              "product_id": "rhosp-rhel9/openstack-keystone",
              "product_identification_helper": {
                "purl": "pkg:oci/openstack-keystone?repository_url=registry.redhat.io/rhosp-rhel9/openstack-keystone"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoso/openstack-keystone-rhel9",
            "product": {
              "name": "rhoso/openstack-keystone-rhel9",
              "product_id": "rhoso/openstack-keystone-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/openstack-keystone-rhel9?repository_url=registry.redhat.io/rhoso/openstack-keystone-rhel9"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openstack-keystone as a component of Red Hat OpenStack Platform 13 (Queens)",
          "product_id": "red_hat_openstack_platform_13_(queens):openstack-keystone"
        },
        "product_reference": "openstack-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_13_(queens)"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openstack-keystone.src as a component of Red Hat OpenStack Platform 13 (Queens)",
          "product_id": "red_hat_openstack_platform_13_(queens):openstack-keystone.src"
        },
        "product_reference": "openstack-keystone.src",
        "relates_to_product_reference": "red_hat_openstack_platform_13_(queens)"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python-keystone as a component of Red Hat OpenStack Platform 13 (Queens)",
          "product_id": "red_hat_openstack_platform_13_(queens):python-keystone"
        },
        "product_reference": "python-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_13_(queens)"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhosp13/openstack-keystone as a component of Red Hat OpenStack Platform 13 (Queens)",
          "product_id": "red_hat_openstack_platform_13_(queens):rhosp13/openstack-keystone"
        },
        "product_reference": "rhosp13/openstack-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_13_(queens)"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openstack-keystone.src as a component of Red Hat OpenStack Platform 16.2",
          "product_id": "red_hat_openstack_platform_16.2:openstack-keystone.src"
        },
        "product_reference": "openstack-keystone.src",
        "relates_to_product_reference": "red_hat_openstack_platform_16.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-keystone as a component of Red Hat OpenStack Platform 16.2",
          "product_id": "red_hat_openstack_platform_16.2:python3-keystone"
        },
        "product_reference": "python3-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_16.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhosp-rhel8/openstack-keystone as a component of Red Hat OpenStack Platform 16.2",
          "product_id": "red_hat_openstack_platform_16.2:rhosp-rhel8/openstack-keystone"
        },
        "product_reference": "rhosp-rhel8/openstack-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_16.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openstack-keystone as a component of Red Hat OpenStack Platform 17.1",
          "product_id": "red_hat_openstack_platform_17.1:openstack-keystone"
        },
        "product_reference": "openstack-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_17.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openstack-keystone.src as a component of Red Hat OpenStack Platform 17.1",
          "product_id": "red_hat_openstack_platform_17.1:openstack-keystone.src"
        },
        "product_reference": "openstack-keystone.src",
        "relates_to_product_reference": "red_hat_openstack_platform_17.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-keystone as a component of Red Hat OpenStack Platform 17.1",
          "product_id": "red_hat_openstack_platform_17.1:python3-keystone"
        },
        "product_reference": "python3-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_17.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhosp-rhel9/openstack-keystone as a component of Red Hat OpenStack Platform 17.1",
          "product_id": "red_hat_openstack_platform_17.1:rhosp-rhel9/openstack-keystone"
        },
        "product_reference": "rhosp-rhel9/openstack-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_17.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openstack-keystone.src as a component of Red Hat OpenStack Platform 18.0",
          "product_id": "red_hat_openstack_platform_18.0:openstack-keystone.src"
        },
        "product_reference": "openstack-keystone.src",
        "relates_to_product_reference": "red_hat_openstack_platform_18.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoso/openstack-keystone-rhel9 as a component of Red Hat OpenStack Platform 18.0",
          "product_id": "red_hat_openstack_platform_18.0:rhoso/openstack-keystone-rhel9"
        },
        "product_reference": "rhoso/openstack-keystone-rhel9",
        "relates_to_product_reference": "red_hat_openstack_platform_18.0"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-42999",
      "cwe": {
        "id": "CWE-639",
        "name": "Authorization Bypass Through User-Controlled Key"
      },
      "discovery_date": "2026-05-28T19:01:53.208887+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2482840"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenStack Keystone. This vulnerability allows an authenticated user to bypass Role-Based Access Control (RBAC) checks by injecting arbitrary policy target attributes into the request body. This enables the user to perform unauthorized operations on resources belonging to other users or projects. The issue stems from the Keystone RBAC policy enforcer unconditionally merging the raw JSON request body into its policy enforcement dictionary, which overwrites trusted data.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via arbitrary policy attribute injection",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This IMPORTANT RBAC bypass vulnerability in Keystone allows authenticated users to inject policy attributes and access other users' resources. Exploitation is straightforward—just include target IDs in the request body. Impact is high to confidentiality and integrity. The scope is unchanged as the attack remains within Keystone's authorization domain. Affects versions since Rocky/14.0.0, fixed in 29.0.2.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "red_hat_openstack_platform_13_(queens):openstack-keystone",
          "red_hat_openstack_platform_13_(queens):openstack-keystone.src",
          "red_hat_openstack_platform_13_(queens):python-keystone",
          "red_hat_openstack_platform_13_(queens):rhosp13/openstack-keystone",
          "red_hat_openstack_platform_16.2:openstack-keystone.src",
          "red_hat_openstack_platform_16.2:python3-keystone",
          "red_hat_openstack_platform_16.2:rhosp-rhel8/openstack-keystone",
          "red_hat_openstack_platform_17.1:openstack-keystone",
          "red_hat_openstack_platform_17.1:openstack-keystone.src",
          "red_hat_openstack_platform_17.1:python3-keystone",
          "red_hat_openstack_platform_17.1:rhosp-rhel9/openstack-keystone",
          "red_hat_openstack_platform_18.0:openstack-keystone.src",
          "red_hat_openstack_platform_18.0:rhoso/openstack-keystone-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-42999"
        },
        {
          "category": "external",
          "summary": "RHBZ#2482840",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2482840"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-42999",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42999"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-42999",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42999"
        },
        {
          "category": "external",
          "summary": "https://bugs.launchpad.net/keystone/+bug/2148398",
          "url": "https://bugs.launchpad.net/keystone/+bug/2148398"
        },
        {
          "category": "external",
          "summary": "https://security.openstack.org/ossa/OSSA-2026-015.html",
          "url": "https://security.openstack.org/ossa/OSSA-2026-015.html"
        }
      ],
      "release_date": "2026-05-28T00:00:00+00:00",
      "remediations": [
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "red_hat_openstack_platform_13_(queens):openstack-keystone",
            "red_hat_openstack_platform_13_(queens):openstack-keystone.src",
            "red_hat_openstack_platform_13_(queens):python-keystone",
            "red_hat_openstack_platform_13_(queens):rhosp13/openstack-keystone",
            "red_hat_openstack_platform_16.2:openstack-keystone.src",
            "red_hat_openstack_platform_16.2:python3-keystone",
            "red_hat_openstack_platform_16.2:rhosp-rhel8/openstack-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone.src",
            "red_hat_openstack_platform_17.1:python3-keystone",
            "red_hat_openstack_platform_17.1:rhosp-rhel9/openstack-keystone",
            "red_hat_openstack_platform_18.0:openstack-keystone.src",
            "red_hat_openstack_platform_18.0:rhoso/openstack-keystone-rhel9"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 8.3,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "red_hat_openstack_platform_13_(queens):openstack-keystone",
            "red_hat_openstack_platform_13_(queens):openstack-keystone.src",
            "red_hat_openstack_platform_13_(queens):python-keystone",
            "red_hat_openstack_platform_13_(queens):rhosp13/openstack-keystone",
            "red_hat_openstack_platform_16.2:openstack-keystone.src",
            "red_hat_openstack_platform_16.2:python3-keystone",
            "red_hat_openstack_platform_16.2:rhosp-rhel8/openstack-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone.src",
            "red_hat_openstack_platform_17.1:python3-keystone",
            "red_hat_openstack_platform_17.1:rhosp-rhel9/openstack-keystone",
            "red_hat_openstack_platform_18.0:openstack-keystone.src",
            "red_hat_openstack_platform_18.0:rhoso/openstack-keystone-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_openstack_platform_13_(queens):openstack-keystone",
            "red_hat_openstack_platform_13_(queens):openstack-keystone.src",
            "red_hat_openstack_platform_13_(queens):python-keystone",
            "red_hat_openstack_platform_13_(queens):rhosp13/openstack-keystone",
            "red_hat_openstack_platform_16.2:openstack-keystone.src",
            "red_hat_openstack_platform_16.2:python3-keystone",
            "red_hat_openstack_platform_16.2:rhosp-rhel8/openstack-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone.src",
            "red_hat_openstack_platform_17.1:python3-keystone",
            "red_hat_openstack_platform_17.1:rhosp-rhel9/openstack-keystone",
            "red_hat_openstack_platform_18.0:openstack-keystone.src",
            "red_hat_openstack_platform_18.0:rhoso/openstack-keystone-rhel9"
          ]
        }
      ],
      "title": "openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via arbitrary policy attribute injection"
    }
  ]
}