Credentials Exposure in OpenStack Ironic - OpenStack Foundation
CVE-2026-90461

6.3MEDIUM

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-90461?

OpenStack Ironic, up to version 38.0.0, has a vulnerability where it may unintentionally transmit a username and password to an unexpected remote host during the configuration of Image Service for HTTP(S) Basic Authentication. This issue could lead to unauthorized access and compromise user accounts, necessitating immediate attention from users who configure Ironic with HTTP(S) Basic Authentication.

Affected Version(s)

Ironic 24.0.0 <= 29.0.6

Ironic 30.0.0 <= 32.0.1

Ironic 33.0.0 <= 35.0.1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.