UNKNOWN OpenStack
CVE-2026-44917
OSSA-2026-019: File Extraction from Ironic conductor via pxe_template
Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io Security Team reported a vulnerability in Ironic’s boot interfaces. A project owner or manager with access to modify node.driver_info[pxe_template] can set it to /etc/ironic/ironic.conf or any other sensitive file readable by the conductor process. Ironic will then place this “template file” into a TFTP or HTTP server for netbooting, where it can be fetched by anything with network access to the conduc
Affected Products
- Ironic: >=17.0.0 <26.1.7, >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2
- CVE-2026-44917
References
- https://security.openstack.org/ossa/OSSA-2026-019.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-44917
This unknown severity vulnerability was published on 2026-06-03 via OpenStack. Affected: Ironic: >=17.0.0 <26.1.7, >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, CVE-2026-44917.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.