Path traversal in OpenStack Ironic - CVE-2026-48681

 

Path traversal in OpenStack Ironic - CVE-2026-48681

Published: June 18, 2026


Vulnerability identifier: #VU134856
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-48681
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to overwrite files on the conductor's disk or target disk.

The vulnerability exists due to path traversal in ISO handling code when processing a crafted ISO image. A remote user can deploy a node using configdrive, a virtual media-based boot interface, or the anaconda deploy interface with a malicious ISO image to overwrite files on the conductor's disk or target disk.

The issue affects both the conductor during ISO handling and the target disk during deployment through the anaconda deploy interface.


Affected software

OpenStack Ironic
Ubuntu
ironic (Ubuntu package)

How to mitigate CVE-2026-48681

Install security update from vendor's website.

OpenStack Ironic - addressed in versions 26.1.7, 29.0.6, 32.0.2, 35.0.2
ironic (Ubuntu package) - addressed in versions 1:20.1.0-0ubuntu1.3, 1:24.1.1-0ubuntu1.3, 1:32.0.0-0ubuntu1.1, 1:35.0.0-0ubuntu2.1

External References

Related Security Bulletins