UNKNOWN OpenStack

CVE-2026-44916

OSSA-2026-012: Remote Code Execution in Ironic conductor when Anaconda driver enabled

Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io Security Team reported a vulnerability in Ironic’s anaconda deploy interface. Users who can set node.instance_info['ks_template'] can achieve remove code execution on the ironic-conductor process, as the template is rendered without sandboxing. In the default configuration, Ironic is not vulnerable to this issue. However, operators who have enabled the anaconda deploy interface by adding it to [conduct

Affected Products

References

Published: 2026-05-11 · Source: OpenStack · Feed updated: 2026-08-04
This unknown severity vulnerability was published on 2026-05-11 via OpenStack. Affected: Ironic: >=17.0.0 <26.1.7, >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, CVE-2026-44916.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.