CVE-2026-54421
EUVD-2026-3665814.06.2026, 04:16
In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openstack | ironic | 17.0.0 ≤ 𝑥 < 29.0.6 | CNA |
| openstack | ironic | 30.0.0 ≤ 𝑥 < 32.0.2 | CNA |
| openstack | ironic | 33.0.0 ≤ 𝑥 < 35.0.2 | CNA |
| openstack | ironic | 36.0.0 ≤ 𝑥 < 37.0.1 | CNA |
Debian Releases
Ubuntu Releases