CVE-2026-42997

OpenStack Ironic has an Incorrect Resource Transfer Between Spheres

Description

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.

Metrics

Severity
high
no public PoC known
7.7
Source: nvd-v3
36.6 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-13 15:15 UTC
CWE-669

Weakness classes (CWE)

  • CWE-669Class

    Incorrect Resource Transfer Between Spheres

    The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-24 20:10 UTC· nvd@nist.gov
    • Translation: Title: Ironic de OpenStack, Description: Se descubrió un problema en idrac en OpenStack Ironic antes de 35.0.1. Durante la importación, un usuario que invoca moldes puede solicitar que se envíe autorización a un punto final remoto. La credencial reenviada es un token de Keystone con límite de tiempo (que proporciona acceso a todos los servicios de OpenStack para los que Ironic está autorizado); o credenciales básicas configuradas para el almacenamiento de moldes. Las versiones corregidas son 26.1.6, 29.0.5, 32.0.1 y 35.0.1.
  2. Initial Analysis2026-06-18 17:12 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* versions from (including) 27.0.0 up to (excluding) 29.0.5 *cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* versions from (including) 30.0.0 up to (excluding) 32.0.1 *cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* versions from (including) 33.0.0 up to (excluding) 35.0.1 *cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* versions from (including) 17.0.0 up to (excluding) 26.1.6
    • Reference Type: MITRE: https://security.openstack.org/ossa/OSSA-2026-010.html Types: Patch, Vendor Advisory
    • Reference Type: MITRE: https://www.openwall.com/lists/oss-security/2026/05/05/10 Types: Mailing List, Patch, Third Party Advisory
    • Reference Type: CVE: http://www.openwall.com/lists/oss-security/2026/05/05/10 Types: Mailing List, Patch, Third Party Advisory

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • pypi

    ironic-python-agent0.0.1

  • pypi

    ironic-python-agent1.0.0

  • pypi

    ironic-python-agent10.0.0

  • pypi

    ironic-python-agent1.0.1

  • pypi

    ironic-python-agent10.1.0

  • pypi

    ironic-python-agent1.0.2

  • pypi

    ironic-python-agent10.2.0

  • pypi

    ironic-python-agent10.2.1

  • pypi

    ironic-python-agent10.2.2

  • pypi

    ironic-python-agent10.2.3

  • pypi

    ironic-python-agent1.0.3

  • pypi

    ironic-python-agent1.0.4

  • pypi

    ironic-python-agent1.0.5

  • pypi

    ironic-python-agent1.1.0

  • pypi

    ironic-python-agent11.0.0

  • pypi

    ironic-python-agent11.1.0

  • pypi

    ironic-python-agent11.2.0

  • pypi

    ironic-python-agent11.3.0

  • pypi

    ironic-python-agent11.4.0

  • pypi

    ironic-python-agent11.5.0

  • pypi

    ironic-python-agent11.6.0

  • pypi

    ironic-python-agent1.2.0

  • pypi

    ironic-python-agent12.0.0

  • pypi

    ironic-python-agent1.2.1

References & sources

IDCVE-2026-42997