PT-2026-46138 · Openstack+2 · Openstack Ironic+2

·

CVE-2026-44917

·

Published

2026-06-04

·

Updated

2026-07-22

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Ironic versions prior to 35.0.2
Description An authenticated project admin or manager can read local files on the Ironic conductor by exploiting the pxe template variable.
Recommendations Update to version 35.0.2 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44917
USN-8421-1

Affected Products

Linuxmint
Openstack Ironic
Ubuntu