UNKNOWN OpenStack

CVE-2026-54421

OSSA-2026-023: Sensitive properties returned unredacted in POST and PATCH HTTP responses

Tuomo Tanskanen (Ericsson Software Technology) and Dmitry Tantsur (Red Hat) of the Metal3.io Security Team discovered a vulnerability in Ironic API RBAC handling, where a user with a valid token and credentials to send a POST or PATCH request to /v1/volume/targets can have potentially sensitive properties returned in the response unredacted, such as iSCSI credentials. Patches ¶ https://review.opendev.org/c/openstack/ironic/+/992335 (2023.1/antelope (unmaintained)) https://review.opendev.org/c/op

Affected Products

References

Published: 2026-06-16 · Source: OpenStack · Feed updated: 2026-08-04
This unknown severity vulnerability was published on 2026-06-16 via OpenStack. Affected: Ironic: >=17.0.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, >=36.0.0 <37.0.1, CVE-2026-54421.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.