Information Disclosure in OpenStack Ironic Affecting Project Data
CVE-2026-71201

5MEDIUM

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71201?

In OpenStack Ironic versions up to 38.0.0, a project reader can exploit a flaw by sending a crafted request to the Ironic service. This allows unauthorized users to retrieve Portgroups associated with Nodes that are owned or leased by different projects, leading to potential exposure of sensitive project information. This vulnerability underscores the importance of ensuring proper access controls within open source cloud infrastructure.

Affected Version(s)

Ironic 1.0.0 <= 29.0.6

Ironic 30.0.0 <= 32.0.1

Ironic 33.0.0 <= 35.0.1

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.