CVE-2026-42997Disclosure(openstack / ironic)

LOWCVSS 7.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-669CWE-201

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ironic

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
ironic

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-05: 3Technical Details · 2026-05-05: 305-05
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    OSSA-2026-010,CVE-2026-42997: OpenStack Ironic: Credential Forwarding to Arbitrary Endpoints via iDrac Configuration Molds Feature https://www.openwall.com/lists/oss-security/2026/05/05/10 A user invoking molds can request authorization to be sent to a remote endpoint. URL is user-controlled.

    Post summary

    The message announces a new vulnerability in OpenStack Ironic where iDrac configuration molds allow user‑controlled URLs to forward credentials to arbitrary endpoints, but it provides no PoC, exploit, patch, or evidence of active exploitation.

    00050457
    4.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42997 An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. Th… https://www.cve.org/CVERecord?id=CVE-2026-42997 ----- Traducción: Se descubrió un pr… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑42997, detailing an authorization request flaw in OpenStack Ironic before v35.0.1 that may send data to a remote endpoint. No PoC, exploits, active attacks, or patch information is supplied.

    0000084
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42997 An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. Th… https://www.cve.org/CVERecord?id=CVE-2026-42997

    Post summary

    The post announces CVE‑2026‑42997 in OpenStack Ironic’s idrac component, detailing that importing user molds may prompt an authorization request to a remote endpoint, without mention of PoC, exploit, or patch.

    00000194
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenstackironic---

Explore more