UNKNOWN OpenStack

CVE-2026-44917

OSSA-2026-019: File Extraction from Ironic conductor via pxe_template

Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io Security Team reported a vulnerability in Ironic’s boot interfaces. A project owner or manager with access to modify node.driver_info[pxe_template] can set it to /etc/ironic/ironic.conf or any other sensitive file readable by the conductor process. Ironic will then place this “template file” into a TFTP or HTTP server for netbooting, where it can be fetched by anything with network access to the conduc

Affected Products

References

Published: 2026-06-03 · Source: OpenStack · Feed updated: 2026-08-04
This unknown severity vulnerability was published on 2026-06-03 via OpenStack. Affected: Ironic: >=17.0.0 <26.1.7, >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, CVE-2026-44917.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.