CVE-2026-42997 Details
Description
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.
A vulnerability exists in OpenStack Ironic versions prior to 35.0.1, specifically in the iDrac configuration molds feature. When importing a configuration mold, an authenticated user can send authorization requests to a remote endpoint. The forwarded credentials include a time-limited Keystone token, granting access to all OpenStack services authorized for Ironic, or basic credentials for molds storage. The vulnerability arises because the authorization request URL is user-controlled and not validated by Ironic, allowing for potential misuse.
Users can upgrade to OpenStack Ironic versions 26.1.6, 29.0.5, 32.0.1, or 35.0.1. For versions 2024.1/caracal and 2026.2/hibiscus, the molds feature has been removed, addressing the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:39811 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-42997 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2466844 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42997.json | redhat-SADP | |
| http://www.openwall.com/lists/oss-security/2026/05/05/10 | CVE | Mailing ListPatchThird Party Advisory |
| https://security.openstack.org/ossa/OSSA-2026-010.html | [email protected] | PatchVendor Advisory |
| https://www.openwall.com/lists/oss-security/2026/05/05/10 | [email protected] | Mailing ListPatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-201 | Insertion of Sensitive Information Into Sent Data | redhat-SADP |
| CWE-669 | Incorrect Resource Transfer Between Spheres | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openstack ironic | >= 17.0.0, < 26.1.6 >= 27.0.0, < 29.0.5 >= 30.0.0, < 32.0.1 >= 33.0.0, < 35.0.1 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 8, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 18, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | CVE Modified | [email protected] |
| May 5, 2026 | CVE Modified | CVE |
| May 5, 2026 | New CVE Received | [email protected] |