PT-2026-46139 · Openstack · Ironic

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2026-48681

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

Fix

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2026-48681

Affected Products

Ironic