UNKNOWN OpenStack
CVE-2026-44916
OSSA-2026-012: Remote Code Execution in Ironic conductor when Anaconda driver enabled
Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io Security Team reported a vulnerability in Ironic’s anaconda deploy interface. Users who can set node.instance_info['ks_template'] can achieve remove code execution on the ironic-conductor process, as the template is rendered without sandboxing. In the default configuration, Ironic is not vulnerable to this issue. However, operators who have enabled the anaconda deploy interface by adding it to [conduct
Affected Products
- Ironic: >=17.0.0 <26.1.7, >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2
- CVE-2026-44916
References
- https://security.openstack.org/ossa/OSSA-2026-012.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-44916
This unknown severity vulnerability was published on 2026-05-11 via OpenStack. Affected: Ironic: >=17.0.0 <26.1.7, >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, CVE-2026-44916.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.