CVE-2026-44918
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/07/2026
Last modified:
10/07/2026
Description
OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://bugs.launchpad.net/ironic/+bug/2150450
- https://lists.openstack.org/archives/list/openstack-announce@lists.openstack.org/thread/PAJKDWS23MKSSNX22JEVDA7RWN3BHJYC/
- https://security.openstack.org/ossa/OSSA-2026-026.html
- https://www.openwall.com/lists/oss-security/2026/07/08/4
- http://www.openwall.com/lists/oss-security/2026/07/08/4



