https://seclists.org/oss-sec/2026/q2/411: [OSSA-2026-010] Ironic: Cdential Forwarding to Arbitrary Endpoints via iDrac Configuration Molds Featu(CVE-2026-42997)
Published May 5, 2026
·Updated
Affected Software
1 affected component
Openstack Ironic>=2024.1<=2026.1
Frequently Asked Questions
1
What is the severity of CVE-2026-42997?
CVE-2026-42997 has been rated as a high severity vulnerability due to its potential to allow credential forwarding to arbitrary endpoints.
2
How do I fix CVE-2026-42997?
To fix CVE-2026-42997, update your OpenStack Ironic installation to the latest patched version provided by your vendor.
3
What systems are affected by CVE-2026-42997?
CVE-2026-42997 specifically affects OpenStack Ironic, particularly those utilizing iDrac configuration molds.
4
What is the impact of CVE-2026-42997 on security?
The impact of CVE-2026-42997 on security is significant, as it could lead to unauthorized access and credential exposure.
5
Is there a workaround for CVE-2026-42997 until a patch is applied?
Currently, no official workaround for CVE-2026-42997 has been provided, so applying the patch is recommended as soon as possible.