← Vulnerability feed

Vulnerability record · CVE-2026-42997 · published 5 May 2026

CVE-2026-42997: Openstack ironic vulnerability

Openstack · Ironic

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.

7.7 CVSS 3.1 High EPSS 0.54% · top 56.6% CWE-669 · CWE-669CWE-201 · CWE-201
7.7CVSS 3.1 base score
0.54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
7References
24 Jul 2026Last modified by NVD

Description

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-42997 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2026-48681Openstack ironic relative path traversal vulnerabilityOpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.EPSS 0.85%7.7CVE-2026-46447Openstack ironic vulnerabilityOpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.EPSS 0.43%7.5CVE-2026-50589Openstack ironic allocation without limits vulnerabilityIn OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC s…EPSS 0.74%7.2CVE-2026-42510Openstack ironic inclusion from untrusted sphere vulnerabilityOpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.EPSS 0.74%6.5CVE-2026-44919Openstack ironic vulnerabilityIn OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero …EPSS 0.56%6.5CVE-2015-7514Openstack ironic information exposure vulnerabilityOpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.EPSS 1.6%4.9CVE-2026-44917Openstack ironic vulnerabilityOpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_templa…EPSS 0.47%3.0CVE-2026-44916Openstack ironic vulnerabilityIn OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2026-42997), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.