CVE-2026-44918: Medium severity Openstack Ironic vulnerability
An authenticated project manager can change the node associated with Volume Connectors or Volume Target objects, potentially changing the project permitted to access the object. Volume Connectors contain secrets in environments configuring boot from volume with iSCSI volumes. This is tracked as bug #2150256.
Other sources
OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch bug #2150256 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 37.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44918?
CVE-2026-44918 has a medium severity rating of 5.5.
How do I fix CVE-2026-44918?
To fix CVE-2026-44918, upgrade OpenStack Ironic to version 37.0.1 or later.
What types of access does CVE-2026-44918 affect?
CVE-2026-44918 allows unauthorized cross-project creation or modification of nodes.
Which software is impacted by CVE-2026-44918?
CVE-2026-44918 impacts OpenStack Ironic prior to version 37.0.1.
When was CVE-2026-44918 published?
CVE-2026-44918 was published on July 10, 2026.