https://seclists.org/oss-sec/2026/q2/936: [OSSA-2026-017] Errata 1: Ironic: Script injection during node boot via linux command line override (CVE-2026-46447)
Published Jun 15, 2026
·Updated
Affected Software
1 affected component
Openstack Ironic
Frequently Asked Questions
1
What is the severity of CVE-2026-46447?
CVE-2026-46447 has been rated as high severity due to its potential for script injection during node boot.
2
How do I fix CVE-2026-46447?
To fix CVE-2026-46447, apply the latest patches provided by OpenStack for Ironic.
3
Which versions of OpenStack Ironic are affected by CVE-2026-46447?
CVE-2026-46447 affects specific versions of OpenStack Ironic prior to the issuance of patched updates.
4
What potential impact does CVE-2026-46447 pose?
CVE-2026-46447 can allow attackers to execute arbitrary scripts during the node boot process.
5
Is there a workaround for CVE-2026-46447 pending a patch?
Until a patch is applied, it is recommended to restrict access to the node boot process to trusted users only.