THREAT OPS › Threat News › [NVD] CVE-2026-40683 (HIGH 7.7) — In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean co
[NVD] CVE-2026-40683 (HIGH 7.7) — In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean co
CVE-2026-40683 CVSS: 7.7 HIGH Published: 2026-04-14T20:16:48.203
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False
Indicators of compromise
- CVE-2026-40683cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40683