UNKNOWN OpenStack

CVE-2026-44918

OSSA-2026-026: Insufficient Access Controls in Ironic regarding Parent/Child Nodes

Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io Security Team reported a vulnerability in Ironic’s access control code. This OSSA represents multiple related vulnerabilities in Ironic RBAC. An authenticated project manager can change the node associated with Volume Connectors or Volume Target objects, potentially changing the project permitted to access the object. Volume Connectors contain secrets in environments configuring boot from volume with i

Affected Products

References

Published: 2026-07-08 · Source: OpenStack · Feed updated: 2026-08-04
This unknown severity vulnerability was published on 2026-07-08 via OpenStack. Affected: Ironic: >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, >=36.0.0 <37.0.1, CVE-2026-44918.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.