File Read Vulnerability in OpenStack Ironic by OpenStack
CVE-2026-44917

4.9MEDIUM

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2026-44917?

OpenStack Ironic versions earlier than 35.0.2 have a file read vulnerability that permits a malicious authenticated project administrator or manager to access local files on the Ironic conductor through a pxe_template. This flaw poses significant security risks as it can lead to the exposure of sensitive data stored on the conductor, potentially impacting the integrity and confidentiality of the environment.

Affected Version(s)

Ironic 17.0.0 < 26.1.7

Ironic 27.0.0 < 29.0.6

Ironic 30.0.0 < 32.0.2

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.