UNKNOWN OpenStack
CVE-2026-46447
OSSA-2026-017: Script injection during node boot via linux command line override
Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io Security Team reported a vulnerability in Ironic’s kernel command line override code. A user with access to add or modify node.driver_info or node.instance_info can create a crafted value to enable iPXE script execution during the boot process.
Affected Products
- Ironic: >=17.0.0 <26.1.7, >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2
- CVE-2026-46447
References
- https://security.openstack.org/ossa/OSSA-2026-017.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-46447
This unknown severity vulnerability was published on 2026-06-03 via OpenStack. Affected: Ironic: >=17.0.0 <26.1.7, >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, CVE-2026-46447.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.