PT-2026-49105 · Openstack · Openstack Ironic

Published

2026-06-14

·

Updated

2026-06-14

·

CVE-2026-54421

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Ironic versions prior to 35.0.2
Description When applying a PATCH request to update fields in volume properties for which a user is authorized, the system may return unredacted sensitive information, such as iSCSI credentials. This issue specifically occurs during the PATCH operation, whereas the POST operation does not result in this disclosure.
Recommendations Update to version 35.0.2 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-54421

Affected Products

Openstack Ironic