CVE-2026-42997
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
Description
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.
Metrics
Weakness classes (CWE)
CWE-669Class
Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Translated2026-07-24 20:10 UTC· nvd@nist.gov
- Translation: Title: Ironic de OpenStack, Description: Se descubrió un problema en idrac en OpenStack Ironic antes de 35.0.1. Durante la importación, un usuario que invoca moldes puede solicitar que se envíe autorización a un punto final remoto. La credencial reenviada es un token de Keystone con límite de tiempo (que proporciona acceso a todos los servicios de OpenStack para los que Ironic está autorizado); o credenciales básicas configuradas para el almacenamiento de moldes. Las versiones corregidas son 26.1.6, 29.0.5, 32.0.1 y 35.0.1.
- Initial Analysis2026-06-18 17:12 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* versions from (including) 27.0.0 up to (excluding) 29.0.5 *cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* versions from (including) 30.0.0 up to (excluding) 32.0.1 *cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* versions from (including) 33.0.0 up to (excluding) 35.0.1 *cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* versions from (including) 17.0.0 up to (excluding) 26.1.6
- Reference Type: MITRE: https://security.openstack.org/ossa/OSSA-2026-010.html Types: Patch, Vendor Advisory
- Reference Type: MITRE: https://www.openwall.com/lists/oss-security/2026/05/05/10 Types: Mailing List, Patch, Third Party Advisory
- Reference Type: CVE: http://www.openwall.com/lists/oss-security/2026/05/05/10 Types: Mailing List, Patch, Third Party Advisory
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
pypi
ironic-python-agent0.0.1
pypi
ironic-python-agent1.0.0
pypi
ironic-python-agent10.0.0
pypi
ironic-python-agent1.0.1
pypi
ironic-python-agent10.1.0
pypi
ironic-python-agent1.0.2
pypi
ironic-python-agent10.2.0
pypi
ironic-python-agent10.2.1
pypi
ironic-python-agent10.2.2
pypi
ironic-python-agent10.2.3
pypi
ironic-python-agent1.0.3
pypi
ironic-python-agent1.0.4
pypi
ironic-python-agent1.0.5
pypi
ironic-python-agent1.1.0
pypi
ironic-python-agent11.0.0
pypi
ironic-python-agent11.1.0
pypi
ironic-python-agent11.2.0
pypi
ironic-python-agent11.3.0
pypi
ironic-python-agent11.4.0
pypi
ironic-python-agent11.5.0
pypi
ironic-python-agent11.6.0
pypi
ironic-python-agent1.2.0
pypi
ironic-python-agent12.0.0
pypi
ironic-python-agent1.2.1
References & sources
- https://nvd.nist.gov/vuln/detail/CVE-2026-42997advisory
- https://github.com/openstack/ironic-python-agentpackage
- https://security.openstack.org/ossa/OSSA-2026-010.htmlweb
- https://www.openwall.com/lists/oss-security/2026/05/05/10web
- http://www.openwall.com/lists/oss-security/2026/05/05/10web
- https://pypi.org/project/ironic-python-agentpackage
- https://github.com/advisories/GHSA-54w4-233h-x86gadvisory
- https://access.redhat.com/security/cve/CVE-2026-42997vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2466844issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42997.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:39811vendor-advisoryx_refsource_REDHAT