CVE-2026-71201: Medium severity Openstack Ironic vulnerability
Published Aug 5, 2026
·Updated
In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.
Affected Software
1 affected component
Openstack Ironic<=38.0.0
Event History
Aug 5, 2026
CVE Published
via MITRE·06:19 AM
Data Sourced
via MITRE·06:19 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-71201?
The severity of CVE-2026-71201 is classified as medium with a score of 5.
2
What does CVE-2026-71201 expose?
CVE-2026-71201 exposes Portgroups assigned to Nodes owned or leased by another project to unauthorized project readers.
3
Which version of OpenStack is affected by CVE-2026-71201?
CVE-2026-71201 affects OpenStack Ironic versions up to and including 38.0.0.
4
How can I mitigate CVE-2026-71201?
To mitigate CVE-2026-71201, ensure proper access controls are implemented to restrict project reader privileges.
5
Is there a fix available for CVE-2026-71201?
As of the publication of CVE-2026-71201, no specific fix has been released; users should monitor OpenStack updates for a resolution.