In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://bugs.launchpad.net/ironic/+bug/2162715 |
|
History
Wed, 05 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross-Project Exposure of Portgroup Assignments |
Wed, 05 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project. | |
| First Time appeared |
Openstack
Openstack ironic |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack ironic |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-05T13:52:41.347Z
Reserved: 2026-08-05T06:19:33.124Z
Link: CVE-2026-71201
Updated: 2026-08-05T13:52:33.594Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T08:00:10Z
Weaknesses