Ironic
Vendor:
First CVE: Jun 7, 2017 · Active for 9 years
13
Total CVEs
More Total CVEs than 91% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ironic over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2017
9 years ago
Most Recent CVE
Jul 10, 2026
14 days ago
CVE Severity & Scoring
Ironic13 CVEs
15%
38%
46%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (7.7%)
Network12 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (84.6%)
High2 (15.4%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (46.2%)
High6 (46.2%)
None1 (7.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54423HIGH In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI | Jul 10, 2026 | 8.2 | 38 | NO | NO |
CVE-2026-48681HIGH OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. | Jun 4, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-46447HIGH OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info. | Jun 3, 2026 | 7.7 | 34 | NO | NO |
CVE-2026-42997HIGH An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential f | May 5, 2026 | 7.7 | 34 | NO | NO |
CVE-2026-50589HIGH In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service cra | Jun 5, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-54421MEDIUM In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such | Jun 14, 2026 | 6.8 | 31 | NO | NO |
CVE-2026-44918MEDIUM OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization. | Jul 10, 2026 | 5.5 | 28 | NO | NO |
CVE-2026-42510HIGH OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. | Apr 28, 2026 | 7.2 | 28 | NO | NO |
CVE-2026-44919MEDIUM In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL. | May 14, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-44917MEDIUM OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template. | Jun 4, 2026 | 4.9 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Ironic
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.2.1 | 1 | 6.5 | 1.6% | 0 | 0 |
| 4.2.0 | 1 | 6.5 | 1.6% | 0 | 0 |