https://seclists.org/oss-sec/2026/q2/798: [OSSA-2026-018] Ironic: File overwrite on Ironic conductor via path traversal in ISO handling (CVE-2026-48681)
Published Jun 3, 2026
·Updated
Affected Software
1 affected component
Openstack Ironic=2026.1 (gazpacho), =2025.2 (flamingo), =2025.1 (epoxy), =34.0 (Bugfix/34.0), =33.0 (Bugfix/33.0)
Frequently Asked Questions
1
What is the severity of CVE-2026-48681?
CVE-2026-48681 has been classified with a high severity due to its potential for file overwriting through path traversal.
2
How do I fix CVE-2026-48681?
To fix CVE-2026-48681, users should update to the latest patched version of OpenStack Ironic as soon as it becomes available.
3
What component of OpenStack is affected by CVE-2026-48681?
CVE-2026-48681 specifically affects the Ironic conductor component of OpenStack.
4
What kind of vulnerability is represented by CVE-2026-48681?
CVE-2026-48681 represents a path traversal vulnerability that can lead to file overwriting.
5
When was CVE-2026-48681 published?
CVE-2026-48681 was published on June 3, 2026.