CVE-2026-71201 Details
Description
In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.
A vulnerability exists in OpenStack Ironic versions through 38.0.0, where a project reader can exploit the portgroup list API. By sending a crafted request that includes a specific shard name, the reader can access portgroups linked to nodes owned or leased by a different project. This issue arises because the shard-based API call fails to apply the necessary project scope filter, allowing unauthorized access to project-specific resources.
Users can upgrade to OpenStack Ironic versions 34.0.0, 37.0.0, or 38.0.0 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugs.launchpad.net/ironic/+bug/2162715 | CISA-ADP | |
| http://www.openwall.com/lists/oss-security/2026/08/05/16 | CVE | |
| https://bugs.launchpad.net/ironic/+bug/2162715 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CVE |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |