9.9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Description
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.
AI Analysis
Privilege escalation and impersonation vulnerability in OpenStack keystonemiddleware via forged authentication headers
Basic Information
ID
CVE-2026-22797
Source
mitre
Published
Jan 19, 2026 at 00:00
Modified
Jan 19, 2026 at 18:08
Affected Product
Vendor
OpenStack
Product
keystonemiddleware
Version
10.5.0
Affected Versions
OpenStack keystonemiddleware 10.5.0
OpenStack keystonemiddleware 10.8.0
OpenStack keystonemiddleware 10.10.0
OpenStack keystonemiddleware 10.8.0
OpenStack keystonemiddleware 10.10.0
CWE Classification
AI Assessment
AI Score
9.9 / 10
AI Severity
Critical
Vendor
OpenStack
Product
keystonemiddleware
Version
10.5.0, 10.7.0, 10.8.0, 10.9.0, 10.10.0, 10.12.0