File Read Vulnerability in OpenStack Ironic by OpenStack
CVE-2026-44917
4.9MEDIUM
What is CVE-2026-44917?
OpenStack Ironic versions earlier than 35.0.2 have a file read vulnerability that permits a malicious authenticated project administrator or manager to access local files on the Ironic conductor through a pxe_template. This flaw poses significant security risks as it can lead to the exposure of sensitive data stored on the conductor, potentially impacting the integrity and confidentiality of the environment.
Affected Version(s)
Ironic 17.0.0 < 26.1.7
Ironic 27.0.0 < 29.0.6
Ironic 30.0.0 < 32.0.2
