https://seclists.org/oss-sec/2026/q2/799: [OSSA-2026-019] Ironic: File Extraction from conductor via pxe_template (CVE-2026-44917)
Published Jun 3, 2026
·Updated
Affected Software
1 affected component
Openstack Ironic
Frequently Asked Questions
1
What is the severity of CVE-2026-44917?
CVE-2026-44917 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2026-44917?
To mitigate CVE-2026-44917, update to the latest version of OpenStack Ironic that includes the security patch.
3
What types of systems are affected by CVE-2026-44917?
CVE-2026-44917 affects installations of OpenStack Ironic that utilize the pxe_template feature.
4
What is the impact of exploiting CVE-2026-44917?
Exploiting CVE-2026-44917 allows an attacker to extract files from the Ironic conductor.
5
When was CVE-2026-44917 published?
CVE-2026-44917 was published on June 3, 2026.