CVE-2026-71201: Openstack Ironic

Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.

In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.

Affected products

  • Openstack Ironic: from 1.0.0, up to and including 29.0.6; from 30.0.0, up to and including 32.0.1; from 33.0.0, up to and including 35.0.1; from 36.0.0, up to and including 38.0.0

Published 2026-08-05. Last modified 2026-09-09.