CVE-2026-22797
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.9epss 0.6%
probabilidad de explotación
0.6%top 56% de las CVE
explotación observada
noninguna fuente lo reporta
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Productos afectados
OpenStack · keystonemiddlewareReferencias
https://access.redhat.com/errata/RHSA-2026:3402https://access.redhat.com/errata/RHSA-2026:3855https://access.redhat.com/errata/RHSA-2026:4434https://access.redhat.com/errata/RHSA-2026:5133https://access.redhat.com/errata/RHSA-2026:5907https://access.redhat.com/security/cve/CVE-2026-22797https://bugzilla.redhat.com/show_bug.cgi?id=2430879https://launchpad.net/bugs/2129018https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22797.jsonhttps://www.openwall.com/lists/oss-security/2026/01/16/9http://www.openwall.com/lists/oss-security/2026/01/15/1http://www.openwall.com/lists/oss-security/2026/01/16/2