OVERVIEW CVE-2026-40683 is a logic error in OpenStack Keystone's LDAP identity backend affecting versions prior to 28.0.1. The vulnerability occurs in the UserApi class where disabled LDAP user accounts are incorrectly treated as enabled when the user_enabled_invert configuration option is set to False (the default setting). This flaw allows disabled users to authenticate and perform actions they should be prohibited from accessing. SEVERITY The vulnerability carries a CVSS score of 7.7 (HIGH) with a network-based attack vector requiring low authentication privileges and medium complexity. The impact is significant, affecting confidentiality, integrity, and availability across organizational boundaries. Exploitation allows unauthorized access by disabled user accounts, potentially leading to data exposure, system modification, and service disruption within multi-tenant OpenStack deployments. EXPLOITATION STATUS There is no indication of active exploitation or public exploit code availability. The CVE does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is classified as inactive on threat tracking lists. However, the moderate FAUCET risk score of 48.0/100 suggests the vulnerability warrants timely patching given its authentication bypass nature and the likelihood that many organizations use LDAP backends with default configurations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 25.0.1CPE match | cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* | ||
>= 26.0.0, < 26.1.1CPE match | cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* | ||
>= 27.0.0, < 27.0.1CPE match | cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* | ||
>= 28.0.0, < 28.0.1CPE match | cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.