UNKNOWN OpenStack

CVE-2026-46447

OSSA-2026-017: Script injection during node boot via linux command line override

Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io Security Team reported a vulnerability in Ironic’s kernel command line override code. A user with access to add or modify node.driver_info or node.instance_info can create a crafted value to enable iPXE script execution during the boot process.

Affected Products

References

Published: 2026-06-03 · Source: OpenStack · Feed updated: 2026-08-04
This unknown severity vulnerability was published on 2026-06-03 via OpenStack. Affected: Ironic: >=17.0.0 <26.1.7, >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, CVE-2026-46447.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.