CVE-2026-46447
published 2026-06-03CVE-2026-46447: OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
PriorityP344high7.7CVSS 3.1
AVNACLPRLUINSCCNIHAN
EPSS
0.26%
17.7th percentile
OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | ironic | >= 17.0.0 < 26.1.7 | 26.1.7 |
| openstack | ironic | >= 17.0.0 < 26.1.7 | 26.1.7 |
| openstack | ironic | >= 27.0.0 < 29.0.6 | 29.0.6 |
| openstack | ironic | >= 27.0.0 < 29.0.6 | 29.0.6 |
| openstack | ironic | >= 30.0.0 < 32.0.2 | 32.0.2 |
| openstack | ironic | >= 30.0.0 < 32.0.2 | 32.0.2 |
| openstack | ironic | >= 33.0.0 < 35.0.2 | 35.0.2 |
| openstack | ironic | >= 33.0.0 < 35.0.2 | 35.0.2 |
| ubuntu | ironic | — | — |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ironic vulnerabilities
vendor_ubuntu·2026-06-11·CVSS 4.9
CVE-2026-48681 [MEDIUM] Ironic vulnerabilities
Title: Ironic vulnerabilities
Summary: Several security issues were fixed in Ironic.
Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic did not
properly validate file paths when handling ISO images. A privileged
authenticated remote user could use this issue to perform path
traversal via a crafted ISO image and overwrite arbitrary files on
the Ironic conductor. (CVE-2026-48681)
Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic did not
properly validate kernel command line parameters. A privileged
authenticated remote user could use this issue to inject
scripts during node boot and possibly execute arbitrary code.
(CVE-2026-46447)
Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic
incorrectly restricted access to custom PXE templates. A privileged
authenticated rem
VulDB
OpenStack Ironic up to 35.0.x injection
vuldb·2026-06-04
CVE-2026-46447 [CRITICAL] OpenStack Ironic up to 35.0.x injection
A vulnerability has been found in OpenStack Ironic up to 35.0.x and classified as critical. The affected element is an unknown function. The manipulation leads to injection.
This vulnerability is documented as CVE-2026-46447. The attack requires being on the local network. There is not any exploit available.
GHSA
OpenStack Ironic through 35.0.x allows Boot Script Injection.
ghsa_unreviewed·2026-06-04
CVE-2026-46447 [MEDIUM] CWE-669 OpenStack Ironic through 35.0.x allows Boot Script Injection.
OpenStack Ironic through 35.0.x allows Boot Script Injection.
GHSA
OpenStack Ironic allows Boot Script Injection
ghsa·2026-06-04
CVE-2026-46447 [MEDIUM] CWE-669 OpenStack Ironic allows Boot Script Injection
OpenStack Ironic allows Boot Script Injection
OpenStack Ironic through 35.0.x allows Boot Script Injection.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-03
Published