CVE-2026-54421 Details
Description
In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.
A vulnerability in OpenStack Ironic versions through 35.0.1 allows for the unredacted return of sensitive information, such as iSCSI credentials, when a user applies a PATCH request to update volume properties they are authorized for. This issue arises because the 'baremetal:volume:view_target_properties' policy is not enforced on PATCH responses, leaving iSCSI connection details, including credentials, exposed. The vulnerability is particularly concerning in multi-tenant deployments where project-scoped users can write to volume targets without the corresponding view-properties permission.
Users can update to OpenStack Ironic versions 35.0.1 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 14, 2026CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/16/10 | CVE | |
| https://bugs.launchpad.net/ironic/+bug/2155049 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://security.openstack.org/ossa/OSSA-2026-023.html | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-212 | Improper Removal of Sensitive Information Before Storage or Transfer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenStack Ironic | <= 35.0.1 (semver) |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CVE |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 14, 2026 | New CVE Received | [email protected] |
Volerion