https://seclists.org/oss-sec/2026/q2/797: [OSSA-2026-017] Ironic: Script injection during node boot via linux command line override (CVE-2026-46447)
Published Jun 3, 2026
·Updated
Affected Software
1 affected component
Openstack Ironic
Frequently Asked Questions
1
What is the severity of CVE-2026-46447?
CVE-2026-46447 is classified with a critical severity due to its potential impact on node boot through script injection.
2
How do I fix CVE-2026-46447?
To mitigate CVE-2026-46447, users should apply the available patches from the OpenStack community.
3
What systems are affected by CVE-2026-46447?
CVE-2026-46447 specifically affects OpenStack Ironic deployments.
4
What type of vulnerability is CVE-2026-46447?
CVE-2026-46447 is a script injection vulnerability that occurs during the node boot process.
5
When was CVE-2026-46447 published?
CVE-2026-46447 was published on June 3, 2026.