{"id":5446,"date":"2026-08-25T17:18:55","date_gmt":"2026-08-25T15:18:55","guid":{"rendered":"https:\/\/yaook.cloud\/?page_id=5446"},"modified":"2026-08-25T17:37:17","modified_gmt":"2026-08-25T15:37:17","slug":"security-advisories-ossa-2026-037","status":"publish","type":"page","link":"https:\/\/yaook.cloud\/en\/security-advisories-ossa-2026-037\/","title":{"rendered":"security-advisories\/ossa-2026-037"},"content":{"rendered":"<div data-elementor-type=\"wp-page\" data-elementor-id=\"5446\" class=\"elementor elementor-5446\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-56e0628 e-flex e-con-boxed e-con e-parent\" data-id=\"56e0628\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-050bc69 elementor-widget elementor-widget-text-editor\" data-id=\"050bc69\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h1>YAOOK Security Advisory for keystone cve-2026-pending OSSA-2026-037<\/h1><ul><li>Date: 25 August 2026<\/li><li>Upstream advisory: <a href=\"https:\/\/security.openstack.org\/ossa\/OSSA-2026-037.html\">https:\/\/security.openstack.org\/ossa\/OSSA-2026-037.html<\/a><\/li><li>Upstream bug: <a href=\"https:\/\/bugs.launchpad.net\/keystone\/+bug\/2153453\">https:\/\/bugs.launchpad.net\/keystone\/+bug\/2153453<\/a> <a href=\"https:\/\/bugs.launchpad.net\/keystone\/+bug\/2158538\">https:\/\/bugs.launchpad.net\/keystone\/+bug\/2158538<\/a><\/li><\/ul><h2>What are OSSA-2026-037 and how do they affect YAOOK?<\/h2><p>Grzegorz Grasza (Red Hat) and Tim Shephard (roiai.ca) independently identified that OpenStack Keystone does not consistently enforce scope restrictions on tokens obtained via delegated authentication methods (ec2credential, application credential, OAuth1 access tokens). The underlying issue is the same: delegated tokens can perform operations or access projects beyond their intended scope. Two separate CVEs have been requested for distinct attack vectors that share this root cause.<\/p><p>Delegation bypass in trust, OAuth 1 and application credential operations (CVE-2026-pending, LP#2153453):<br \/>Tokens obtained via EC2 credential authentication can create new application credentials and authorise OAuth1 request tokens, thereby establishing new delegations that persist independently of the original credential and survive its revocation. Both EC2 and OAuth1 tokens can create trusts that delegate roles beyond the scope of the requesting token, because trust role validation checks the trustor\u2019s full role assignments rather than the token\u2019s scoped roles.<\/p><p>Token reauthentication escape (CVE-2026-pending, LP#2158538):<br \/>Tokens obtained via application credential or EC2 credential authentication can escape their intended project scope through token-method reauthentication. An application credential token scoped to a single project can be exchanged via a POST request to \/v3\/auth\/tokens without an explicit scope, causing Keystone to issue a new token scoped to the owner\u2019s default project. For EC2-derived tokens, the bypass is more widespread: as they do not carry any delegation markers, they can be rescoped to any project where the underlying user has role assignments.<\/p><h2>Is my cluster vulnerable?<\/h2><div>The following images are vulnerable:<\/div><ul><li>Keystone images prior to version 3.0.94<\/li><li>yaook release prior to 3.4.0<\/li><\/ul><div>If this image is used in your cluster for the Keystone deployment, the cluster is vulnerable.<\/div><div>\u00a0<\/div><div>The fixed image has been built in a <a href=\"https:\/\/gitlab.com\/yaook-security\/images\/keystone\/-\/pipelines\/2789490776\">private pipeline<\/a> which has been published alongside this advisory to prove the image provenance.<\/div><h2>Upgrading<\/h2><div>A new stable release will be published according to the release cycle and hotfix releases will be produced starting now. You can upgrade to that release simply by updating your operators.<\/div><div>\u00a0<\/div><div>However, we recommend adding a <a title=\"https:\/\/docs.yaook.cloud\/user\/references\/env-reference.html#envvar-YAOOK_OP_VERSIONS_OVERRIDE\" href=\"https:\/\/docs.yaook.cloud\/user\/references\/env-reference.html#envvar-YAOOK_OP_VERSIONS_OVERRIDE\" target=\"_blank\" rel=\"noopener noreferrer\">YAOOK_OP_VERSIONS_OVERRIDE<\/a> variable to your Keystone operator container to pull the image before the YAOOK comprehensive release is ready.<\/div><div>\u00a0<\/div><div>The best way to do this is to set the following in the values.yaml of your keystone-operator (make sure to merge this correctly with an existing values.yaml, if you have that).<\/div><pre class=\"rcx-box rcx-box--full rcx-css-1siaxf\" role=\"region\" data-code-block-wrapper=\"true\"><code class=\"code-colors language-yaml hljs\"><span class=\"hljs-attr\">operator:<\/span>\n    <span class=\"hljs-attr\">extraEnv:<\/span>\n    <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-attr\">name:<\/span> <span class=\"hljs-string\">YAOOK_OP_VERSIONS_OVERRIDE<\/span>\n    <span class=\"hljs-attr\">value:<\/span> <span class=\"hljs-string\">|\n {\n \"registry.yaook.cloud\/yaook\/keystone-2024.1\": \"registry.yaook.cloud\/yaook\/keystone-2024.1:3.0.94\",\n \"registry.yaook.cloud\/yaook\/keystone-2024.2\": \"registry.yaook.cloud\/yaook\/keystone-2024.2:3.0.94\",\n \"registry.yaook.cloud\/yaook\/keystone-2025.1\": \"registry.yaook.cloud\/yaook\/keystone-2025.1:3.0.94\",\n            \"registry.yaook.cloud\/yaook\/keystone-2025.2\": \"registry.yaook.cloud\/yaook\/keystone-2025.2:3.0.94\",<br \/>            \"registry.yaook.cloud\/yaook\/keystone-2026.1\": \"registry.yaook.cloud\/yaook\/keystone-2026.1:3.0.94\"\n }<\/span><\/code><\/pre><div>If you are not using Helm, you can add the environment variable to the <code class=\"code-colors inline\">env<\/code> section of your keystone-operator's Deployment's pod template.<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>YAOOK Security Advisory for keystone cve-2026-pending OSSA-2026-037 Date: 2026-08-25 Upstream advisory: https:\/\/security.openstack.org\/ossa\/OSSA-2026-037.html Upstream bug: https:\/\/bugs.launchpad.net\/keystone\/+bug\/2153453 https:\/\/bugs.launchpad.net\/keystone\/+bug\/2158538 What are OSSA-2026-037 and how do they affect YAOOK? Grzegorz Grasza (Red Hat) and Tim Shephard (roiai.ca) independently identified that OpenStack Keystone does not consistently enforce scope restrictions on tokens obtained via delegated authentication methods (ec2credential, application credential, OAuth1 [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"class_list":["post-5446","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>security-advisories\/ossa-2026-037 &#187; Yaook<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/yaook.cloud\/en\/security-advisories-ossa-2026-037\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"security-advisories\/ossa-2026-037 &#187; Yaook\" \/>\n<meta property=\"og:description\" content=\"YAOOK Security Advisory for keystone cve-2026-pending OSSA-2026-037 Date: 2026-08-25 Upstream advisory: https:\/\/security.openstack.org\/ossa\/OSSA-2026-037.html Upstream bug: https:\/\/bugs.launchpad.net\/keystone\/+bug\/2153453 https:\/\/bugs.launchpad.net\/keystone\/+bug\/2158538 What are OSSA-2026-037 and how do they affect YAOOK? Grzegorz Grasza (Red Hat) and Tim Shephard (roiai.ca) independently identified that OpenStack Keystone does not consistently enforce scope restrictions on tokens obtained via delegated authentication methods (ec2credential, application credential, OAuth1 [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/yaook.cloud\/en\/security-advisories-ossa-2026-037\/\" \/>\n<meta property=\"og:site_name\" content=\"Yaook\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-25T15:37:17+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/yaook.cloud\\\/security-advisories-ossa-2026-037\\\/\",\"url\":\"https:\\\/\\\/yaook.cloud\\\/security-advisories-ossa-2026-037\\\/\",\"name\":\"security-advisories\\\/ossa-2026-037 &#187; Yaook\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/yaook.cloud\\\/#website\"},\"datePublished\":\"2026-08-25T15:18:55+00:00\",\"dateModified\":\"2026-08-25T15:37:17+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/yaook.cloud\\\/security-advisories-ossa-2026-037\\\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/yaook.cloud\\\/security-advisories-ossa-2026-037\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/yaook.cloud\\\/security-advisories-ossa-2026-037\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/yaook.cloud\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"security-advisories\\\/ossa-2026-037\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/yaook.cloud\\\/#website\",\"url\":\"https:\\\/\\\/yaook.cloud\\\/\",\"name\":\"Yaook\",\"description\":\"The Lifecycle Management Tool for OpenStack\",\"publisher\":{\"@id\":\"https:\\\/\\\/yaook.cloud\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/yaook.cloud\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/yaook.cloud\\\/#organization\",\"name\":\"ALASCA e.V.\",\"alternateName\":\"Alasca - Verband f\u00fcr betriebsf\u00e4hige, offene Cloud-Infrastrukturen e.V.\",\"url\":\"https:\\\/\\\/yaook.cloud\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/yaook.cloud\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/alasca.cloud\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/favicon.png\",\"contentUrl\":\"https:\\\/\\\/alasca.cloud\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/favicon.png\",\"width\":512,\"height\":512,\"caption\":\"ALASCA e.V.\"},\"image\":{\"@id\":\"https:\\\/\\\/yaook.cloud\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"security-advisories\/ossa-2026-037 \u00bb Yaook","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/yaook.cloud\/en\/security-advisories-ossa-2026-037\/","og_locale":"en_GB","og_type":"article","og_title":"security-advisories\/ossa-2026-037 &#187; Yaook","og_description":"YAOOK Security Advisory for keystone cve-2026-pending OSSA-2026-037 Date: 2026-08-25 Upstream advisory: https:\/\/security.openstack.org\/ossa\/OSSA-2026-037.html Upstream bug: https:\/\/bugs.launchpad.net\/keystone\/+bug\/2153453 https:\/\/bugs.launchpad.net\/keystone\/+bug\/2158538 What are OSSA-2026-037 and how do they affect YAOOK? Grzegorz Grasza (Red Hat) and Tim Shephard (roiai.ca) independently identified that OpenStack Keystone does not consistently enforce scope restrictions on tokens obtained via delegated authentication methods (ec2credential, application credential, OAuth1 [&hellip;]","og_url":"https:\/\/yaook.cloud\/en\/security-advisories-ossa-2026-037\/","og_site_name":"Yaook","article_modified_time":"2026-08-25T15:37:17+00:00","twitter_card":"summary_large_image","twitter_misc":{"Estimated reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/yaook.cloud\/security-advisories-ossa-2026-037\/","url":"https:\/\/yaook.cloud\/security-advisories-ossa-2026-037\/","name":"security-advisories\/ossa-2026-037 \u00bb Yaook","isPartOf":{"@id":"https:\/\/yaook.cloud\/#website"},"datePublished":"2026-08-25T15:18:55+00:00","dateModified":"2026-08-25T15:37:17+00:00","breadcrumb":{"@id":"https:\/\/yaook.cloud\/security-advisories-ossa-2026-037\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/yaook.cloud\/security-advisories-ossa-2026-037\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/yaook.cloud\/security-advisories-ossa-2026-037\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/yaook.cloud\/"},{"@type":"ListItem","position":2,"name":"security-advisories\/ossa-2026-037"}]},{"@type":"WebSite","@id":"https:\/\/yaook.cloud\/#website","url":"https:\/\/yaook.cloud\/","name":"Yaook","description":"The Lifecycle Management Tool for OpenStack","publisher":{"@id":"https:\/\/yaook.cloud\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/yaook.cloud\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/yaook.cloud\/#organization","name":"ALASCA e.V.","alternateName":"Alasca - Verband f\u00fcr betriebsf\u00e4hige, offene Cloud-Infrastrukturen e.V.","url":"https:\/\/yaook.cloud\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/yaook.cloud\/#\/schema\/logo\/image\/","url":"https:\/\/alasca.cloud\/wp-content\/uploads\/2022\/08\/favicon.png","contentUrl":"https:\/\/alasca.cloud\/wp-content\/uploads\/2022\/08\/favicon.png","width":512,"height":512,"caption":"ALASCA e.V."},"image":{"@id":"https:\/\/yaook.cloud\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/yaook.cloud\/en\/wp-json\/wp\/v2\/pages\/5446","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/yaook.cloud\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/yaook.cloud\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/yaook.cloud\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/yaook.cloud\/en\/wp-json\/wp\/v2\/comments?post=5446"}],"version-history":[{"count":17,"href":"https:\/\/yaook.cloud\/en\/wp-json\/wp\/v2\/pages\/5446\/revisions"}],"predecessor-version":[{"id":5464,"href":"https:\/\/yaook.cloud\/en\/wp-json\/wp\/v2\/pages\/5446\/revisions\/5464"}],"wp:attachment":[{"href":"https:\/\/yaook.cloud\/en\/wp-json\/wp\/v2\/media?parent=5446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}