Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40683

29
FAUCET Score

OVERVIEW CVE-2026-40683 is a logic error in OpenStack Keystone's LDAP identity backend affecting versions prior to 28.0.1. The vulnerability occurs in the UserApi class where disabled LDAP user accounts are incorrectly treated as enabled when the user_enabled_invert configuration option is set to False (the default setting). This flaw allows disabled users to authenticate and perform actions they should be prohibited from accessing. SEVERITY The vulnerability carries a CVSS score of 7.7 (HIGH) with a network-based attack vector requiring low authentication privileges and medium complexity. The impact is significant, affecting confidentiality, integrity, and availability across organizational boundaries. Exploitation allows unauthorized access by disabled user accounts, potentially leading to data exposure, system modification, and service disruption within multi-tenant OpenStack deployments. EXPLOITATION STATUS There is no indication of active exploitation or public exploit code availability. The CVE does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is classified as inactive on threat tracking lists. However, the moderate FAUCET risk score of 48.0/100 suggests the vulnerability warrants timely patching given its authentication bypass nature and the likelihood that many organizations use LDAP backends with default configurations.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.0.0, < 25.0.1CPE match
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
>= 26.0.0, < 26.1.1CPE match
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
>= 27.0.0, < 27.0.1CPE match
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
>= 28.0.0, < 28.0.1CPE match
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.3
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
24.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 13th percentile among its peer group of 1,162 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

pippatch availablevia ghsa
Product: keystoneFixed in: 28.0.1
ubuntupatch availablevia ubuntu_usn
Product: keystone (jammy)Fixed in: 2:21.0.1-0ubuntu2.4
ubuntupatch availablevia ubuntu_usn
Product: keystone (noble)Fixed in: 2:25.0.0-0ubuntu1.4
ubuntupatch availablevia ubuntu_usn
Product: keystone (questing)Fixed in: 2:28.0.0-0ubuntu1.3
ubuntupatch availablevia ubuntu_usn
Product: keystone (resolute)Fixed in: 2:29.0.0-0ubuntu1.2

Vendor Advisories (2)

ubuntuUSN-8433-1

OpenStack Keystone vulnerabilities

Jun 16, 2026
pipGHSA-pfx2-9x9m-7ghxhigh

OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean

Apr 14, 2026

References

bugs.launchpad.net / keystone/+bug/2121152
bugs.launchpad.net / keystone/+bug/2141713
review.opendev.org / 958205
openwall.com / lists/oss-security/2026/04/14/9