CVE-2026-44916 Details
Description
In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.
A vulnerability in OpenStack Ironic versions through 35.x allows for Jinja2 template injection, which can be exploited to achieve remote code execution. The issue arises because instance_info['ks_template'] is rendered using an unsandboxed Jinja2 environment, enabling authenticated users to inject malicious templates that are fetched and executed on the server side. This vulnerability is particularly concerning in kickstart-based deployments using the Anaconda deployment interface.
The vulnerability has been fixed in the OpenStack Ironic master branch and backported to the stable/2026.1 branch. Users should upgrade to version 2026.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/05/11/7 | CVE | Mailing ListPatchThird Party Advisory |
| https://bugs.launchpad.net/ironic/+bug/2148307 | [email protected] | Issue TrackingMitigationThird Party Advisory |
| https://security.openstack.org/ossa/OSSA-2026-012.html | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1336 | Improper Neutralization of Special Elements Used in a Template Engine | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openstack ironic | >= 17.0.0, < 26.1.7 >= 27.0.0, < 29.0.6 >= 30.0.0, < 32.0.2 >= 33.0.0, < 35.0.2 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 20, 2026 | CVE Modified | [email protected] |
| May 12, 2026 | CVE Modified | [email protected] |
| May 11, 2026 | CVE Modified | CVE |
| May 8, 2026 | New CVE Received | [email protected] |