4.9
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Description
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
Basic Information
ID
CVE-2026-44917
Source
mitre
Published
Jun 4, 2026 at 00:00
Modified
Jun 4, 2026 at 03:36
Affected Product
Vendor
OpenStack
Product
Ironic
Version
17.0.0
Affected Versions
OpenStack Ironic 17.0.0
OpenStack Ironic 27.0.0
OpenStack Ironic 30.0.0
OpenStack Ironic 33.0.0
OpenStack Ironic 27.0.0
OpenStack Ironic 30.0.0
OpenStack Ironic 33.0.0