CVE-2026-48681
published 2026-06-04CVE-2026-48681: OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
PriorityP351high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.60%
44.8th percentile
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | ironic | >= 17.0.0 < 26.1.7 | 26.1.7 |
| openstack | ironic | >= 17.0.0 < 26.1.7 | 26.1.7 |
| openstack | ironic | >= 27.0.0 < 29.0.6 | 29.0.6 |
| openstack | ironic | >= 27.0.0 < 29.0.6 | 29.0.6 |
| openstack | ironic | >= 30.0.0 < 32.0.2 | 32.0.2 |
| openstack | ironic | >= 30.0.0 < 32.0.2 | 32.0.2 |
| openstack | ironic | >= 33.0.0 < 35.0.2 | 35.0.2 |
| openstack | ironic | >= 33.0.0 < 35.0.2 | 35.0.2 |
| ubuntu | ironic | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat8.1HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenStack Ironic up to 26.1.6/29.0.5/32.0.1/35.0.1 ISO Image path traversal (EUVD-2026-34203 / Nessus ID 320843)
vuldb·2026-06-12·CVSS 8.1
CVE-2026-48681 [HIGH] OpenStack Ironic up to 26.1.6/29.0.5/32.0.1/35.0.1 ISO Image path traversal (EUVD-2026-34203 / Nessus ID 320843)
A vulnerability has been found in OpenStack Ironic up to 26.1.6/29.0.5/32.0.1/35.0.1 and classified as problematic. This impacts an unknown function of the component ISO Image Handler. This manipulation causes relative path traversal.
This vulnerability is registered as CVE-2026-48681. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
GHSA
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
ghsa_unreviewed·2026-06-04
CVE-2026-48681 [MEDIUM] CWE-23 OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
GHSA
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
ghsa·2026-06-04
CVE-2026-48681 [MEDIUM] CWE-23 OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
Ubuntu
Ironic vulnerabilities
vendor_ubuntu·2026-06-11·CVSS 4.9
CVE-2026-48681 [MEDIUM] Ironic vulnerabilities
Title: Ironic vulnerabilities
Summary: Several security issues were fixed in Ironic.
Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic did not
properly validate file paths when handling ISO images. A privileged
authenticated remote user could use this issue to perform path
traversal via a crafted ISO image and overwrite arbitrary files on
the Ironic conductor. (CVE-2026-48681)
Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic did not
properly validate kernel command line parameters. A privileged
authenticated remote user could use this issue to inject
scripts during node boot and possibly execute arbitrary code.
(CVE-2026-46447)
Dmitry Tantsur and Tuomo Tanskanen discovered that Ironic
incorrectly restricted access to custom PXE templates. A privileged
authenticated rem
Red Hat
openstack-ironic: OpenStack Ironic: File overwrite via directory traversal vulnerability
vendor_redhat·2026-06-04·CVSS 8.1
CVE-2026-48681 [HIGH] CWE-22 openstack-ironic: OpenStack Ironic: File overwrite via directory traversal vulnerability
openstack-ironic: OpenStack Ironic: File overwrite via directory traversal vulnerability
A flaw was found in OpenStack Ironic (before 35.0.2). A directory traversal vulnerability during deployment allows an attacker to overwrite files on the system when a crafted ISO image is used. This can compromise confidentiality and integrity of files on the deployment target.
Statement: OpenStack Ironic is vulnerable to directory traversal during node deployment when processing a crafted ISO image, allowing file overwrite on the target system. A remote attacker with high privileges who can initiate deployments with attacker-controlled ISO content could read or modify files (confidentiality and integrity impact). CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N (5.9). Affects OpenStack 16.2, 17.1, 18.0,
No detection rules found.
No public exploits indexed.
2026-06-04
Published