← Vulnerability feed

Vulnerability record · CVE-2026-46447 · published 3 June 2026

CVE-2026-46447: Openstack ironic vulnerability

Openstack · Ironic

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

7.7 CVSS 3.1 High EPSS 0.43% · top 65.0% CWE-669 · CWE-669
7.7CVSS 3.1 base score
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
22 Jul 2026Last modified by NVD

Description

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-46447 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2026-48681Openstack ironic relative path traversal vulnerabilityOpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.EPSS 0.85%7.7CVE-2026-42997Openstack ironic vulnerabilityAn issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a re…EPSS 0.54%7.5CVE-2026-50589Openstack ironic allocation without limits vulnerabilityIn OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC s…EPSS 0.74%7.2CVE-2026-42510Openstack ironic inclusion from untrusted sphere vulnerabilityOpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.EPSS 0.74%6.5CVE-2026-44919Openstack ironic vulnerabilityIn OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero …EPSS 0.56%6.5CVE-2015-7514Openstack ironic information exposure vulnerabilityOpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.EPSS 1.6%4.9CVE-2026-44917Openstack ironic vulnerabilityOpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_templa…EPSS 0.47%3.0CVE-2026-44916Openstack ironic vulnerabilityIn OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2026-46447), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.