OpenStack Admin Forgery: CVE-2026-22797 Lets Users ‘Ask’ for Root
ID: 2ecef8d6-0fe7-5c3b-906d-56c448107907
STIX ID: report--2ecef8d6-0fe7-5c3b-906d-56c448107907
Feed Name: securityonline.info
**Executive Summary:** A critical privilege-escalation vulnerability (CVE-2026-22797) was found in OpenStack's keystonemiddleware external_oauth2_token middleware that fails to sanitize incoming authentication headers, allowing authenticated users to spoof headers (such as X-Is-Admin-Project, X-Roles, and X-User-Id) and potentially gain administrative privileges or impersonate other users; patches have been released across multiple OpenStack release branches and administrators are urged to apply them immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
