CVE-2026-42997
published 2026-05-05CVE-2026-42997: An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote…
PriorityP349high7.7CVSS 3.1
AVNACLPRLUINSCCHINAN
EPSS
0.44%
35.6th percentile
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | ironic | >= 17.0.0 < 26.1.6 | 26.1.6 |
| openstack | ironic | >= 27.0.0 < 29.0.5 | 29.0.5 |
| openstack | ironic | >= 30.0.0 < 32.0.1 | 32.0.1 |
| openstack | ironic | >= 33.0.0 < 35.0.1 | 35.0.1 |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
ghsa·2026-05-05
CVE-2026-42997 [HIGH] CWE-669 OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.
VulDB
OpenStack Ironic up to 26.1.5/29.0.4/32.0.0/35.0.0 idrac resource transfer (EUVD-2026-27428)
vuldb·2026-05-05·CVSS 7.7
CVE-2026-42997 [HIGH] OpenStack Ironic up to 26.1.5/29.0.4/32.0.0/35.0.0 idrac resource transfer (EUVD-2026-27428)
A vulnerability identified as problematic has been detected in OpenStack Ironic up to 26.1.5/29.0.4/32.0.0/35.0.0. Impacted is an unknown function of the component idrac. The manipulation leads to incorrect resource transfer.
This vulnerability is listed as CVE-2026-42997. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
GHSA
GHSA-54w4-233h-x86g: An issue was discovered in idrac in OpenStack Ironic before 35
ghsa_unreviewed·2026-05-05
CVE-2026-42997 [HIGH] CWE-669 GHSA-54w4-233h-x86g: An issue was discovered in idrac in OpenStack Ironic before 35
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.
Red Hat
OpenStack Ironic: OpenStack Ironic: Information disclosure via credential forwarding during mold import
vendor_redhat·2026-05-05·CVSS 7.7
CVE-2026-42997 [HIGH] CWE-201 OpenStack Ironic: OpenStack Ironic: Information disclosure via credential forwarding during mold import
OpenStack Ironic: OpenStack Ironic: Information disclosure via credential forwarding during mold import
A flaw was found in OpenStack Ironic. During the import process, a user invoking molds can request that authorization credentials be sent to a remote endpoint. This can lead to the disclosure of a time-limited Keystone token, which grants access to OpenStack services Ironic is authorized for, or basic credentials configured for molds storage. This information disclosure could allow an attacker to gain unauthorized access to other OpenStack services.
Statement: This IMPORTANT information disclosure vulnerability in OpenStack Ironic allows authenticated users to forward credentials to attacker-controlled endpoints during mold import. The scope is changed as disclosed credentials can acce
No detection rules found.
No public exploits indexed.
https://security.openstack.org/ossa/OSSA-2026-010.htmlhttps://www.openwall.com/lists/oss-security/2026/05/05/10http://www.openwall.com/lists/oss-security/2026/05/05/10https://access.redhat.com/errata/RHSA-2026:39811https://access.redhat.com/security/cve/CVE-2026-42997https://bugzilla.redhat.com/show_bug.cgi?id=2466844https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42997.json
2026-05-05
Published