CVE-2026-48681: [OSSA-2026-018] Ironic: File overwrite on Ironic conductor via path traversal in ISO handling (CVE-2026-48681)
Published Jun 3, 2026
·Updated
Last updated 6 June 2026
Other sources
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
— NVD
Affected Software
6 affected componentsFixes available
Openstack Ironic<35.0.2
Openstack Ironic>=17.0.0<26.1.7
Openstack Ironic>=27.0.0<29.0.6
Openstack Ironic>=30.0.0<32.0.2
Openstack Ironic>=33.0.0<35.0.2
debian/ironic<=1:16.0.3-1, <=1:21.1.0-3, <=1:29.0.0-7, <=1:35.0.1-5, <=1:35.0.1-6
1:21.4.4-0+deb12u11:29.0.5-0+deb13u2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ironicto a version that resolves this vulnerability.Fixed in 1:21.4.4-0+deb12u1Fixed in 1:29.0.5-0+deb13u2 - Upgrade
Upgrade
OpenStack Ironicto a version that resolves this vulnerability.Fixed in 35.0.2Patch OSSA-2026-018
Event History
Jun 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeaknessAffected Software
Jun 11, 2026
Data Sourced
via Ubuntu·11:16 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·11:17 PM
Description
Jun 16, 2026
Data Sourced
via Debian·11:21 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48681?
CVE-2026-48681 has a high severity rating of 8.1.
2
How do I fix CVE-2026-48681?
To fix CVE-2026-48681, upgrade OpenStack Ironic to version 35.0.2 or later.
3
What type of vulnerability is CVE-2026-48681?
CVE-2026-48681 is a directory traversal vulnerability that allows file overwrite.
4
What software is affected by CVE-2026-48681?
CVE-2026-48681 affects OpenStack Ironic versions before 35.0.2.
5
What can be exploited in CVE-2026-48681?
CVE-2026-48681 can be exploited through a crafted ISO image leading to file overwrite.