Sceawere

Vulnerability Detail

CVE-2026-74250UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenStack Ironic Autodetect Deploy Interface Cleaning Failure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
5h ago
Vendor
OpenStack
Product
Ironic
Attack Type
CWE-226 Sensitive Information in Resource Not Removed Before Reuse
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-08-14T23:16:34.853Z",
  "pubdate": "2026-08-14T23:16:34.853Z",
  "executiveSummary": "A logic flaw exists in OpenStack Ironic prior to version 38.0.1 within the autodetect deploy interface.\nThe vulnerability causes the system to fail in executing automated node cleaning procedures immediately following enrollment or when switching to the autodetect deploy interface.\nThis impacts system integrity and configuration management within cloud environments utilizing OpenStack Ironic for bare metal provisioning.\nThe risk implications involve uncleaned bare metal nodes transitioning between tenants or states without proper sanitization, potentially retaining residual data or inconsistent configurations.\nAttacker capabilities depend on administrative or provisioning access to the Ironic API to enroll nodes or modify deploy interfaces.\nExploitation requirements include interacting with the Ironic control plane during node lifecycle state transitions.",
  "technicalDetails": "The root cause of the vulnerability resides in the state machine and logic handling of the autodetect deploy interface within OpenStack Ironic.\nSpecifically, when a bare metal node is initially enrolled using the autodetect deploy interface, or when an operator explicitly changes an existing node's deploy interface to the autodetect mechanism, the expected transition triggering automated node cleaning routines fails to execute.\nThe vulnerable component is the autodetect deploy interface handler responsible for queueing cleaning steps during node state changes.\nAffected versions include OpenStack Ironic deployments prior to version 38.0.1.\nAuthentication and privilege requirements typically map to operator or administrative privileges capable of interacting with the Ironic API to manage node lifecycles, enroll hardware, and alter driver configurations.\nNetwork exposure is constrained to the OpenStack management network hosting the Ironic API service.\nThe step-by-step attack flow involves an actor enrolling a bare metal node or modifying its deploy interface to the autodetect option. Due to the implementation flaw, the state machine bypasses or fails to invoke the mandatory cleaning cycle that normally sanitizes local storage and resets firmware configurations between allocations.\nPost-exploitation impact includes potential data remanence on disks if nodes are subsequently provisioned to different tenants without prior manual intervention, leading to unauthorized data exposure across multi-tenant boundaries."
}
CVE-2026-74250: OpenStack Ironic Autodetect Deploy Interface Cleaning Failure (MEDIUM Severity, CVSS: 6.3) - Sceawere