CyberRota Analysis
AI-GeneratedOpenStack Ironic versions prior to 37.0.1 are vulnerable to unauthorized cross-project creation or modification of nodes, potentially allowing attackers to manipulate resources across different projects. This could lead to unauthorized access and control over cloud infrastructure components. Organizations using OpenStack Ironic should prioritize this vulnerability to mitigate risks associated with unauthorized resource management.
CVE
CVE-2026-44918
Severity
MEDIUM
CVSS
5.5
EPSS
0.33%
Original NVD Description
OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.