CVE-2026-54421

In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.
Configurations

No configuration.

History

23 Jul 2026, 10:10

Type Values Removed Values Added
Summary
  • (es) En OpenStack Ironic hasta la versión 35.0.1, al aplicar un parche para actualizar campos en las propiedades de volumen para las que el usuario está autorizado, Ironic puede devolver información sensible sin redactar (como credenciales iSCSI). El resultado de la operación PATCH es un problema de seguridad; el resultado de la operación POST no es un problema de seguridad.

17 Jun 2026, 13:20

Type Values Removed Values Added
Summary (en) In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue. (en) In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.
References
  • () https://security.openstack.org/ossa/OSSA-2026-023.html -
  • () http://www.openwall.com/lists/oss-security/2026/06/16/10 -

14 Jun 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-14 04:16

Updated : 2026-07-23 10:10


NVD link : CVE-2026-54421

Mitre link : CVE-2026-54421

CVE.ORG link : CVE-2026-54421


JSON object : View

Products Affected

No product.

CWE
CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer