CVE-2026-44918
published 2026-07-10CVE-2026-44918: OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
PriorityP431medium5.5CVSS 3.1
AVNACLPRHUINSUCHILAN
EPSS
0.43%
34.4th percentile
OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | ironic | >= 27.0.0 < 29.0.6 | 29.0.6 |
| openstack | ironic | >= 30.0.0 < 32.0.2 | 32.0.2 |
| openstack | ironic | >= 33.0.0 < 35.0.2 | 35.0.2 |
| openstack | ironic | >= 36.0.0 < 37.0.1 | 37.0.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-ironic: Prevent rehoming resources to nodes with different owner
vendor_redhat·2026-07-08·CVSS 8.7
CVE-2026-44918 [HIGH] CWE-1220 openstack-ironic: Prevent rehoming resources to nodes with different owner
openstack-ironic: Prevent rehoming resources to nodes with different owner
A flaw was found in OpenStack Ironic. An authenticated project manager can change the node associated with Volume Connectors or Volume Target objects, potentially changing the project permitted to access the object. Volume Connectors contain secrets in environments configuring boot from volume with iSCSI volumes. Additionally, a project manager with the ability to create nodes can use the UUID of a node not owned by their project as a parent node when creating a new node. This mismatched child node can then be used to impact operations on the parent, such as forcing it to power on.
Statement: The Red Hat Product Security team has assessed the severity of this vulnerability as Important. An authenticated project ma
GHSA
OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
ghsa_unreviewed·2026-07-10
CVE-2026-44918 [MEDIUM] CWE-862 OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
No detection rules found.
No public exploits indexed.
https://bugs.launchpad.net/ironic/+bug/2150450https://lists.openstack.org/archives/list/[email protected]/thread/PAJKDWS23MKSSNX22JEVDA7RWN3BHJYC/https://security.openstack.org/ossa/OSSA-2026-026.htmlhttps://www.openwall.com/lists/oss-security/2026/07/08/4http://www.openwall.com/lists/oss-security/2026/07/08/4
2026-07-10
Published