UNKNOWN OpenStack

CVE-2026-48681

OSSA-2026-018: File overwrite on Ironic conductor via path traversal in ISO handling

Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io Security Team reported a vulnerability in Ironic’s ISO handling code. A maliciously crafted ISO image can cause Ironic to perform path traversal and overwrite files on a conductor’s disk. Similarly, in the anaconda deploy interface, the same vulnerability can be exploited to perform path traversal and overwrite files on the target disk during deployment. Any Ironic user who has access to deploy nodes u

Affected Products

References

Published: 2026-06-03 · Source: OpenStack · Feed updated: 2026-08-04
This unknown severity vulnerability was published on 2026-06-03 via OpenStack. Affected: Ironic: >=17.0.0 <26.1.7, >=27.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, CVE-2026-48681.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.