← Vulnerability feed

Vulnerability record · CVE-2026-44916 · published 8 May 2026

CVE-2026-44916: Openstack ironic vulnerability

Openstack · Ironic

In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.

3.0 CVSS 3.1 Low EPSS 0.35% · top 73.6% CWE-1336 · CWE-1336
3.0CVSS 3.1 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
18 Jun 2026Last modified by NVD

Description

In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugs.launchpad.net/ironic/+bug/2148307 Issue TrackingMitigationThird Party Advisory
https://security.openstack.org/ossa/OSSA-2026-012.html PatchVendor Advisory
http://www.openwall.com/lists/oss-security/2026/05/11/7 Mailing ListPatchThird Party Advisory

Track CVE-2026-44916 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2026-48681Openstack ironic relative path traversal vulnerabilityOpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.EPSS 0.85%7.7CVE-2026-46447Openstack ironic vulnerabilityOpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.EPSS 0.43%7.7CVE-2026-42997Openstack ironic vulnerabilityAn issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a re…EPSS 0.54%7.5CVE-2026-50589Openstack ironic allocation without limits vulnerabilityIn OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC s…EPSS 0.74%7.2CVE-2026-42510Openstack ironic inclusion from untrusted sphere vulnerabilityOpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.EPSS 0.74%6.5CVE-2026-44919Openstack ironic vulnerabilityIn OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero …EPSS 0.56%6.5CVE-2015-7514Openstack ironic information exposure vulnerabilityOpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.EPSS 1.6%4.9CVE-2026-44917Openstack ironic vulnerabilityOpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_templa…EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2026-44916), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.