UNKNOWN OpenStack
CVE-2026-44918
OSSA-2026-026: Insufficient Access Controls in Ironic regarding Parent/Child Nodes
Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io Security Team reported a vulnerability in Ironic’s access control code. This OSSA represents multiple related vulnerabilities in Ironic RBAC. An authenticated project manager can change the node associated with Volume Connectors or Volume Target objects, potentially changing the project permitted to access the object. Volume Connectors contain secrets in environments configuring boot from volume with i
Affected Products
- Ironic: >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, >=36.0.0 <37.0.1
- CVE-2026-44918
References
- https://security.openstack.org/ossa/OSSA-2026-026.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-44918
This unknown severity vulnerability was published on 2026-07-08 via OpenStack. Affected: Ironic: >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, >=36.0.0 <37.0.1, CVE-2026-44918.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.