CVE-2026-71201
EUVD-2026-5312405.08.2026, 07:16
In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openstack | ironic | 1.0.0 ≤ 𝑥 ≤ 29.0.6 | CNA |
| openstack | ironic | 30.0.0 ≤ 𝑥 ≤ 32.0.1 | CNA |
| openstack | ironic | 33.0.0 ≤ 𝑥 ≤ 35.0.1 | CNA |
| openstack | ironic | 36.0.0 ≤ 𝑥 ≤ 38.0.0 | CNA |
Debian Releases