CyberRota Analysis
AI-GeneratedOpenStack Ironic versions up to 38.0.0 are vulnerable to unauthorized exposure of Portgroups, allowing a project reader to access information about Nodes owned or leased by other projects through crafted requests. This could lead to information disclosure, potentially impacting the confidentiality of project resources. Organizations utilizing OpenStack Ironic should prioritize this vulnerability to mitigate the risk of sensitive data exposure.
CVE
CVE-2026-71201
Severity
MEDIUM
CVSS
5
EPSS
0.17%
Original NVD Description
In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.