CVE-2026-44917
published 2026-06-04CVE-2026-44917: OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
PriorityP427medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.28%
20.6th percentile
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | ironic | >= 17.0.0 < 26.1.7 | 26.1.7 |
| openstack | ironic | >= 27.0.0 < 29.0.6 | 29.0.6 |
| openstack | ironic | >= 30.0.0 < 32.0.2 | 32.0.2 |
| openstack | ironic | >= 33.0.0 < 35.0.2 | 35.0.2 |
| ubuntu | ironic | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenStack Ironic up to 26.1.6/29.0.5/32.0.1/35.0.1 on Ironic resource transfer (EUVD-2026-34202 / Nessus ID 320843)
vuldb·2026-06-13·CVSS 4.9
CVE-2026-44917 [MEDIUM] OpenStack Ironic up to 26.1.6/29.0.5/32.0.1/35.0.1 on Ironic resource transfer (EUVD-2026-34202 / Nessus ID 320843)
A vulnerability was found in OpenStack Ironic up to 26.1.6/29.0.5/32.0.1/35.0.1 on Ironic. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in incorrect resource transfer.
This vulnerability is reported as CVE-2026-44917. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
GHSA
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
ghsa_unreviewed·2026-06-04
CVE-2026-44917 [MEDIUM] CWE-669 OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
Ubuntu
Ironic vulnerabilities
vendor_ubuntu·2026-06-11·CVSS 4.9
CVE-2026-48681 [MEDIUM] Ironic vulnerabilities
Title: Ironic vulnerabilities
Summary: Several security issues were fixed in Ironic.
Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic did not
properly validate file paths when handling ISO images. A privileged
authenticated remote user could use this issue to perform path
traversal via a crafted ISO image and overwrite arbitrary files on
the Ironic conductor. (CVE-2026-48681)
Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic did not
properly validate kernel command line parameters. A privileged
authenticated remote user could use this issue to inject
scripts during node boot and possibly execute arbitrary code.
(CVE-2026-46447)
Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic
incorrectly restricted access to custom PXE templates. A privileged
authenticated rem
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-04
Published