Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6341-1 | ironic security update |
Thu, 04 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 04 Jun 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Project Admin File Read via PXE Template in OpenStack Ironic |
Thu, 04 Jun 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template. | |
| First Time appeared |
Openstack
Openstack ironic |
|
| Weaknesses | CWE-669 | |
| CPEs | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack ironic |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-04T13:07:33.838Z
Reserved: 2026-05-08T00:00:00.000Z
Link: CVE-2026-44917
Updated: 2026-06-04T05:40:39.892Z
Status : Analyzed
Published: 2026-06-04T04:17:14.853
Modified: 2026-06-04T18:40:49.520
Link: CVE-2026-44917
No data.
OpenCVE Enrichment
Updated: 2026-06-04T07:00:09Z
Debian DSA