VYPR
Medium severity5.8NVD Advisory· Published Jun 3, 2026· Updated Jul 22, 2026

CVE-2026-46447

CVE-2026-46447

Description

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ironicPyPI
>= 17.0.0, < 26.1.726.1.7
ironicPyPI
>= 27.0.0, < 29.0.629.0.6
ironicPyPI
>= 30.0.0, < 32.0.232.0.2
ironicPyPI
>= 33.0.0, < 35.0.235.0.2

Affected products

2
  • OpenStack/Ironicllm-fuzzy2 versions
    <35.0.2+ 1 more
    • (no CPE)range: <35.0.2
    • cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*range: >=17.0.0,<26.1.7

Patches

Vulnerability mechanics

References

6

News mentions

1