OpenStack Ironic Insufficient Access Control Vulnerability in Node Management

Vulnerability

A vulnerability exists in OpenStack Ironic versions prior to 37.0.1, allowing unauthorized cross-project creation or modification of nodes. This issue arises from inadequate role-based access control (RBAC) checks, enabling project managers to manipulate node associations with Volume Connectors or Volume Targets, potentially altering access permissions for sensitive data, particularly in environments using iSCSI for boot volumes. Additionally, project managers can exploit this vulnerability by reparenting nodes to disrupt normal operations, such as power management, on parent nodes.

Impact

Exploitation of this vulnerability can lead to unauthorized access to sensitive information contained in Volume Connectors, as well as disruption of node management operations, particularly in relation to power controls and instance provisioning through the Nova driver.

Reproduction

To reproduce this vulnerability, an authenticated project manager must create a node and assign it a parent node from a different project, bypassing the ownership verification. This can be done by using the UUID of a node not owned by the project, effectively creating a child node that can interfere with the parent's operations. Additionally, reparenting nodes with mismatched owners can be done through the Ironic API, which will disrupt normal power management processes.

Remediation

Users can update to Ironic versions 37.0.1 or later, where this vulnerability has been addressed. Instructions for applying the update can be found in the OpenStack Ironic documentation.

Added: Jul 10, 2026, 4:26 AM
Updated: Jul 10, 2026, 4:26 AM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
0.6
exploitability
5.8
remediation
8.3
relevance
9.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.