Improper Neutralization of Special Elements in Output Used by a Downstream Component in OpenStack Ironic - CVE-2026-46447

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in OpenStack Ironic - CVE-2026-46447

Published: June 18, 2026


Vulnerability identifier: #VU134855
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-46447
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute iPXE script code during node boot.

The vulnerability exists due to improper neutralization of special elements in Ironic's kernel command line override code when processing crafted values in node.driver_info or node.instance_info. A remote user can supply a crafted override value to execute iPXE script code during node boot.

Exploitation requires the ability to add or modify node.driver_info or node.instance_info.


Affected software

OpenStack Ironic
Ubuntu
ironic (Ubuntu package)

How to mitigate CVE-2026-46447

Install security update from vendor's website.

OpenStack Ironic - addressed in versions 26.1.7, 29.0.6, 32.0.2, 35.0.2
ironic (Ubuntu package) - addressed in versions 1:20.1.0-0ubuntu1.3, 1:24.1.1-0ubuntu1.3, 1:32.0.0-0ubuntu1.1, 1:35.0.0-0ubuntu2.1

External References

Related Security Bulletins