UNKNOWN OpenStack
CVE-2026-54421
OSSA-2026-023: Sensitive properties returned unredacted in POST and PATCH HTTP responses
Tuomo Tanskanen (Ericsson Software Technology) and Dmitry Tantsur (Red Hat) of the Metal3.io Security Team discovered a vulnerability in Ironic API RBAC handling, where a user with a valid token and credentials to send a POST or PATCH request to /v1/volume/targets can have potentially sensitive properties returned in the response unredacted, such as iSCSI credentials. Patches ¶ https://review.opendev.org/c/openstack/ironic/+/992335 (2023.1/antelope (unmaintained)) https://review.opendev.org/c/op
Affected Products
- Ironic: >=17.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, >=36.0.0 <37.0.1
- CVE-2026-54421
References
- https://security.openstack.org/ossa/OSSA-2026-023.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-54421
This unknown severity vulnerability was published on 2026-06-16 via OpenStack. Affected: Ironic: >=17.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, >=36.0.0 <37.0.1, CVE-2026-54421.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.