https://seclists.org/oss-sec/2026/q3/96: [OSSA-2026-026] Ironic: Insufficient Access Controls garding pant/child nodes
Published Jul 8, 2026
·Updated
Affected Software
8 affected components
Openstack Ironic
Openstack Ironic<2025.1
Openstack Ironic<2025.2
Openstack Ironic<2026.1
Openstack Ironic<2026.2
Openstack Ironic<33.0
Openstack Ironic<34.0
Openstack Ironic<37.0
Frequently Asked Questions
1
What is the severity of CVE-2026-44918?
CVE-2026-44918 is classified as a medium severity vulnerability due to insufficient access controls.
2
How do I fix CVE-2026-44918?
To fix CVE-2026-44918, ensure that all access controls for parent/child nodes are correctly configured in OpenStack Ironic.
3
What systems are affected by CVE-2026-44918?
CVE-2026-44918 affects the OpenStack Ironic component of the OpenStack software.
4
What is the impact of exploiting CVE-2026-44918?
Exploiting CVE-2026-44918 can allow unauthorized users to gain access to sensitive parent/child node information.
5
When was CVE-2026-44918 published?
CVE-2026-44918 was published on July 8, 2026.