CVE-2026-44918: Openstack Ironic
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
Affected products
- Openstack Ironic: from 27.0.0, before 29.0.6 (fixed in 29.0.6); from 30.0.0, before 32.0.2 (fixed in 32.0.2); from 33.0.0, before 35.0.2 (fixed in 35.0.2); from 36.0.0, before 37.0.1 (fixed in 37.0.1)
Published 2026-07-10. Last modified 2026-07-10.