UNKNOWN OpenStack
CVE-2026-71201
OSSA-2026-033: Portgroup shard filter bypasses project scope
Chen YuXiang of Institute of Computing Technology, Chinese Academy of Sciences reported an issue in Ironic’s API. When a project reader requests a list of portgroups filtered by shard, all portgroups in that shard are returned, not just those in their project. This is a similar vulnerability to the one originally advisoried in OSSA-2026-026 – that issue impacted ports; this impacts portgroups. Patches ¶ https://review.opendev.org/999762 (2026.1/gazpacho) https://review.opendev.org/999656 (2026.2
Affected Products
- Ironic: >=34.0.0 <35.0.2, >=36.0.0 <38.0.1
- CVE-2026-71201
References
- https://security.openstack.org/ossa/OSSA-2026-033.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-71201
This unknown severity vulnerability was published on 2026-08-05 via OpenStack. Affected: Ironic: >=34.0.0 <35.0.2, >=36.0.0 <38.0.1, CVE-2026-71201.
vulnfeed aggregates 14146 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.