CVE-2026-46447: [OSSA-2026-017] Ironic: Script injection during node boot via linux command line override (CVE-2026-46447)
Last updated 6 June 2026
Other sources
OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driverinfo or node.instanceinfo.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ironicto a version that resolves this vulnerability.Fixed in 1:21.4.4-0+deb12u1Fixed in 1:29.0.5-0+deb13u2 - Upgrade
Upgrade
OpenStack Ironicto a version that resolves this vulnerability.Fixed in 35.0.2Patch OSSA-2026-017
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46447?
The severity of CVE-2026-46447 is high, with a CVSS score of 7.7.
How do I fix CVE-2026-46447?
You can fix CVE-2026-46447 by applying the available patch for OpenStack Ironic.
What type of vulnerability is CVE-2026-46447?
CVE-2026-46447 is a script injection vulnerability that affects OpenStack Ironic.
Which versions of OpenStack Ironic are affected by CVE-2026-46447?
OpenStack Ironic versions before 35.0.2 are affected by CVE-2026-46447.
What can an attacker achieve by exploiting CVE-2026-46447?
By exploiting CVE-2026-46447, an attacker can perform Boot Script Injection during the node boot process.