VYPR
Medium severity5.9NVD Advisory· Published Jun 4, 2026· Updated Jul 22, 2026

CVE-2026-48681

CVE-2026-48681

Description

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ironicPyPI
>= 17.0.0, < 26.1.726.1.7
ironicPyPI
>= 27.0.0, < 29.0.629.0.6
ironicPyPI
>= 30.0.0, < 32.0.232.0.2
ironicPyPI
>= 33.0.0, < 35.0.235.0.2

Affected products

2
  • OpenStack/Ironic2 versions
    cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*range: >=17.0.0,<26.1.7
    • (no CPE)range: <35.0.2

Patches

Vulnerability mechanics

References

5

News mentions

1