CVE-2026-54421: [OSSA-2026-023] Ironic: Sensitive properties turned undacted in POST and PATCH HTTP sponses (CVE-2026-54421)
In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenStack Ironicto a version that resolves this vulnerability.Fixed in 37.0.1Patch OSSA-2026-023
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54421?
CVE-2026-54421 has a medium severity score of 6.8.
What systems are affected by CVE-2026-54421?
CVE-2026-54421 affects OpenStack Ironic versions up to and including 35.0.1.
What type of vulnerability is CVE-2026-54421?
CVE-2026-54421 is a security issue related to unauthorized exposure of sensitive information when applying PATCH requests.
How do I fix CVE-2026-54421?
To mitigate CVE-2026-54421, update to a patched version of OpenStack Ironic after version 35.0.1.
What sensitive information is exposed in CVE-2026-54421?
CVE-2026-54421 can expose sensitive information such as iSCSI credentials during unauthorized PATCH requests.