5.9
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Description
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
Basic Information
ID
CVE-2026-48681
Source
mitre
Published
Jun 4, 2026 at 00:00
Modified
Jun 4, 2026 at 03:27
Affected Product
Vendor
OpenStack
Product
Ironic
Version
17.0.0
Affected Versions
OpenStack Ironic 17.0.0
OpenStack Ironic 27.0.0
OpenStack Ironic 30.0.0
OpenStack Ironic 33.0.0
OpenStack Ironic 27.0.0
OpenStack Ironic 30.0.0
OpenStack Ironic 33.0.0