Known vulnerabilities in OpenStack Ironic

Vendor: Openstack
Software CPE: cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
Total vulnerabilities: 7
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenStack Ironic OpenStack Ironic is affected by 7 known vulnerabilities: 2 medium, 5 low Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU134857 - Improper Access Control
CVE-2026-44917
CWE-284 Low
No
No
26.1.7, 29.0.6, 32.0.2, 35.0.2 18.06.2026 SB2026061841
SB2026061857
#VU134856 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-48681
CWE-22 Low
No
No
26.1.7, 29.0.6, 32.0.2, 35.0.2 18.06.2026 SB2026061841
SB2026061857
#VU134855 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-46447
CWE-74 Low
No
No
26.1.7, 29.0.6, 32.0.2, 35.0.2 18.06.2026 SB2026061841
SB2026061857
#VU134851 - Improper Access Control
CVE-2026-54421
CWE-284 Low
No
No
29.0.6, 32.0.2, 35.0.2, 37.0.1 18.06.2026 SB2026061837
#VU128242 - Command injection
CWE-77 Medium
No
No
26.1.6, 29.0.5, 32.0.1, 35.0.1 27.04.2026 SB20260427189
#VU98123 - Improper Validation of Integrity Check Value
CVE-2024-47211
CWE-354 Medium
No
No
21.4.4, 23.0.3, 24.1.3, 26.1.0 08.10.2024 SB2024100260
SB2024102305
SB2024103012
and 2 more
#VU97965 - Improper Access Control
CVE-2024-44082
CWE-284 Low
No
No
21.4.3, 23.0.2, 24.1.2, 26.1.0 02.10.2024 SB2024100260
SB2024100261
SB2024100262
and 10 more