https://seclists.org/oss-sec/2026/q2/477: [OSSA-2026-012] Ironic: mote Code Execution when Anaconda driver enabled (CVE-2026-44916)
Published May 11, 2026
·Updated
Affected Software
1 affected component
Openstack Ironic
Frequently Asked Questions
1
What is the severity of CVE-2026-44916?
CVE-2026-44916 is considered critical due to the potential for remote code execution when the Anaconda driver is enabled.
2
How do I fix CVE-2026-44916?
To fix CVE-2026-44916, users should apply the security patches provided in the updated OpenStack Ironic release.
3
What systems are affected by CVE-2026-44916?
CVE-2026-44916 affects installations of OpenStack Ironic with the Anaconda driver enabled.
4
Can CVE-2026-44916 be exploited remotely?
Yes, CVE-2026-44916 can be exploited remotely, allowing attackers to execute arbitrary code on the affected system.
5
Is there a workaround for CVE-2026-44916 while waiting for a patch?
A temporary workaround for CVE-2026-44916 is to disable the Anaconda driver, though this may limit certain functionality.