logo

OpenStack Keystone Flaw Grants Access to Disabled LDAP Users

ID: 8d891b1d-a385-5d83-b9c1-01e3f84124f9

STIX ID: report--8d891b1d-a385-5d83-b9c1-01e3f84124f9

Feed Name: securityonline.info

Threat Score
55/100

Date Published: 2026-04-15

Date Updated: 2026-04-23

Author: Ddos

...
...

A logic bug in OpenStack Keystone's LDAP integration causes the LDAP "enabled" attribute to be misinterpreted when user_enabled_invert is False, allowing users disabled in LDAP to still authenticate. The issue affects several recent releases (2024.2, 2025.1, 2025.2, 2026.1) and is fixed in Gazpacho (29.0.0); administrators can mitigate by setting user_enabled_invert=True or using user_enabled_emulation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.