{"id":"CVE-2026-44394","aliases":["GHSA-whqr-fgm5-x77q","PYSEC-2026-603"],"url":"https://o3.security/vulnerability/CVE-2026-44394","summary":"OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token","details":"An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected.","published":"2026-05-28T00:00:00Z","modified":"2026-08-12T03:51:26.868423055Z","cvss":{"score":6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L"},"epss":{"score":0.00249,"percentile":0.1598,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"keystone","fixedVersion":"27.0.2"},{"ecosystem":"PyPI","name":"keystone","fixedVersion":"28.0.2"},{"ecosystem":"PyPI","name":"keystone","fixedVersion":"29.0.2"}],"fix":null,"references":[{"type":"WEB","url":"https://bugs.launchpad.net/keystone/+bug/2150379"},{"type":"WEB","url":"https://security.openstack.org/ossa/OSSA-2026-015.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44394.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44394"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.868423055Z"}}