CVE-2026-44918 Details
Description
OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
A vulnerability exists in OpenStack Ironic versions prior to 37.0.1, allowing unauthorized cross-project creation or modification of nodes. This issue arises from inadequate role-based access control (RBAC) checks, enabling project managers to manipulate node associations with Volume Connectors or Volume Targets, potentially altering access permissions for sensitive data, particularly in environments using iSCSI for boot volumes. Additionally, project managers can exploit this vulnerability by reparenting nodes to disrupt normal operations, such as power management, on parent nodes.
Users can update to Ironic versions 37.0.1 or later, where this vulnerability has been addressed. Instructions for applying the update can be found in the OpenStack Ironic documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/08/4 | CVE | AdvisoryMailing List |
| https://bugs.launchpad.net/ironic/+bug/2150450 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://lists.openstack.org/archives/list/[email protected]/thread/PAJKDWS23MKSSNX22JEVDA7RWN3BHJYC/ | [email protected] | AdvisoryMailing ListRemedyVendor |
| https://security.openstack.org/ossa/OSSA-2026-026.html | [email protected] | AdvisoryBundleRemedyVendor |
| https://www.openwall.com/lists/oss-security/2026/07/08/4 | [email protected] | AdvisoryMailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenStack Ironic | >= 27.0.0, < 29.0.6 (semver) >= 30.0.0, < 32.0.2 (semver) >= 33.0.0, < 35.0.2 (semver) >= 36.0.0, < 37.0.1 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |
| Jul 10, 2026 | CVE Modified | CVE |
Volerion