- What: Security update for openstack-keystone in Red Hat OpenStack Platform 17.1
- Impact: Systems using openstack-keystone may be vulnerable to privilege escalation
Red Hat Product Errata RHSA-2026:28044 - Security Advisory Issued: 2026-06-22 Updated: 2026-06-22 RHSA-2026:28044 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat OpenStack Platform 17.1 (openstack-keystone) security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for openstack-keystone is now available for Red Hat OpenStack Platform 17.1 (Wallaby). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Keystone is a Python implementation of the OpenStack ( http://www.openstack.org ) identity service API. Security Fix(es): OpenStack Keystone: Privilege escalation through EC2 credential creation (CVE-2026-33551) OpenStack Keystone: Unauthenticated access to EC2/S3 token endpoints can grant Keystone authorization (CVE-2025-65073) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat OpenStack 17.1 for RHEL 9 x86_64 Fixes BZ - 2415344 - CVE-2025-65073 openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via AWS signature validation flaw BZ - 2451037 - CVE-2026-33551 openstack-keystone: OpenStack Keystone: Privilege escalation through EC2 credential creation CVEs CVE-2025-65073 CVE-2026-33551 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat OpenStack 17.1 for RHEL 9 SRPM openstack-keystone-19.0.2-17.1.20260529190847.54dd95d.el9ost.src.rpm SHA-256: 4c2b460b47d1eed47f11f779230816061e209e62cd547b868a378c2dfe4d6365 openstack-swift-2.27.1-17.1.20231004180819.el9ost.src.rpm SHA-256: ff82e96fd66769928a4ef114b4a8b8f2aa78a68a84d4a984771d60a20b5ccb5c openstack-tempest-33.0.0-17.1.20260406141650.1580f6f.el9ost.src.rpm SHA-256: eafa0fc4bdac8d59ff5ed81a5ab5942a2c827fd1a3d70e7e62792d6632e28f35 x86_64 openstack-keystone-19.0.2-17.1.20260529190847.54dd95d.el9ost.noarch.rpm SHA-256: 407a02abbe2bb17722c3abfeeea3a9dc009c31dbe40a6cba87532c3404800ae8 openstack-swift-account-2.27.1-17.1.20231004180819.el9ost.noarch.rpm SHA-256: 96dfb558d21e6fc4d69dd72bccff11f248f8fa306b14f0faf27d990bbd51f48c openstack-swift-container-2.27.1-17.1.20231004180819.el9ost.noarch.rpm SHA-256: f062ea02983da5dd1cb68a8f94d9f3d0c504659ac47fda4d603dba1a55e7cefc openstack-swift-object-2.27.1-17.1.20231004180819.el9ost.noarch.rpm SHA-256: 1f12b1dac935c3a778086b3c995267dbc4eec1896bab2cb4d612b1dc1ab152d4 openstack-swift-proxy-2.27.1-17.1.20231004180819.el9ost.noarch.rpm SHA-256: 74a55a2c4c67983971a4ea4486928764d6e8f545878f4b3f1e91a97359096038 openstack-tempest-33.0.0-17.1.20260406141650.1580f6f.el9ost.noarch.rpm SHA-256: eaef967d296916271a5b2b5278964dc9f86c6b46250093b5003a1877f2b42fb0 openstack-tempest-all-33.0.0-17.1.20260406141650.1580f6f.el9ost.noarch.rpm SHA-256: 0f531909c59842de618dbacbf8082260380b7f0f95daa946dd7b5c35b515c632 python3-keystone-19.0.2-17.1.20260529190847.54dd95d.el9ost.noarch.rpm SHA-256: 1cf404418c0d1c5d42172fd2fa42502f80f10a511e58eabb1e719b42dc188bc1 python3-swift-2.27.1-17.1.20231004180819.el9ost.noarch.rpm SHA-256: 0e55d702945e2a4234738c2d934e421ef3168a888202c2c483cf708b2dbcd533 python3-tempest-33.0.0-17.1.20260406141650.1580f6f.el9ost.noarch.rpm SHA-256: dfd5092f5e0775b8adfd6a7d415473648e03d811988de58318fb526cf39c4bba python3-tempest-tests-33.0.0-17.1.20260406141650.1580f6f.el9ost.noarch.rpm SHA-256: b0c4de2b1abcf6c2578b428440834918b9bdc6bf95909ff7f21824736b59d755 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .