PT-2026-49105 · Openstack · Openstack Ironic

·

CVE-2026-54421

·

Published

2026-06-14

·

Updated

2026-09-10

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Ironic versions prior to 35.0.2
Description When applying a PATCH request to update fields in volume properties for which a user is authorized, the system may return unredacted sensitive information, such as iSCSI credentials. This issue specifically occurs during the PATCH operation, whereas the POST operation does not result in this disclosure.
Recommendations Update to version 35.0.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54421
GHSA-J4CW-MCG2-2Q78
PYSEC-2026-3852

Affected Products

Openstack Ironic