Path traversal in OpenStack Ironic - CVE-2026-48681
Published: June 18, 2026
Vulnerability details
The vulnerability allows a remote user to overwrite files on the conductor's disk or target disk.
The vulnerability exists due to path traversal in ISO handling code when processing a crafted ISO image. A remote user can deploy a node using configdrive, a virtual media-based boot interface, or the anaconda deploy interface with a malicious ISO image to overwrite files on the conductor's disk or target disk.
The issue affects both the conductor during ISO handling and the target disk during deployment through the anaconda deploy interface.
Affected software
Ubuntu
ironic (Ubuntu package)
How to mitigate CVE-2026-48681
ironic (Ubuntu package) - addressed in versions 1:20.1.0-0ubuntu1.3, 1:24.1.1-0ubuntu1.3, 1:32.0.0-0ubuntu1.1, 1:35.0.0-0ubuntu2.1