
OSSA-2026-012,CVE-2026-44916: OpenStack Ironic: Remote Code Execution when Anaconda driver enabled https://www.openwall.com/lists/oss-security/2026/05/11/7 Users who can set node.instance_info['ks_template'] can achieve RCE on the ironic-conductor process, as the template is rendered without sandboxing
Post summary
The passage announces a new Remote Code Execution flaw in OpenStack Ironic’s Anaconda driver. It highlights the vulnerability mechanism—unsandboxed rendering of ks_template—without indicating active exploitation or available patches.


