CVE-2026-71201 PUBLISHED

Assigner: mitre
Reserved: 05.08.2026 Published: 05.08.2026 Updated: 05.08.2026

In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS Score: 5

Product Status

Vendor OpenStack
Product Ironic
Versions Default: unaffected
  • affected from 1.0.0 to 29.0.6 (incl.)
  • affected from 30.0.0 to 32.0.1 (incl.)
  • affected from 33.0.0 to 35.0.1 (incl.)
  • affected from 36.0.0 to 38.0.0 (incl.)

References

Problem Types

  • CWE-863 Incorrect Authorization CWE