Sceawere
Vulnerability Detail
CVE-2026-74250UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OpenStack Ironic Autodetect Deploy Interface Cleaning Failure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 5h ago
- Vendor
- OpenStack
- Product
- Ironic
- Attack Type
- CWE-226 Sensitive Information in Resource Not Removed Before Reuse
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-08-14T23:16:34.853Z",
"pubdate": "2026-08-14T23:16:34.853Z",
"executiveSummary": "A logic flaw exists in OpenStack Ironic prior to version 38.0.1 within the autodetect deploy interface.\nThe vulnerability causes the system to fail in executing automated node cleaning procedures immediately following enrollment or when switching to the autodetect deploy interface.\nThis impacts system integrity and configuration management within cloud environments utilizing OpenStack Ironic for bare metal provisioning.\nThe risk implications involve uncleaned bare metal nodes transitioning between tenants or states without proper sanitization, potentially retaining residual data or inconsistent configurations.\nAttacker capabilities depend on administrative or provisioning access to the Ironic API to enroll nodes or modify deploy interfaces.\nExploitation requirements include interacting with the Ironic control plane during node lifecycle state transitions.",
"technicalDetails": "The root cause of the vulnerability resides in the state machine and logic handling of the autodetect deploy interface within OpenStack Ironic.\nSpecifically, when a bare metal node is initially enrolled using the autodetect deploy interface, or when an operator explicitly changes an existing node's deploy interface to the autodetect mechanism, the expected transition triggering automated node cleaning routines fails to execute.\nThe vulnerable component is the autodetect deploy interface handler responsible for queueing cleaning steps during node state changes.\nAffected versions include OpenStack Ironic deployments prior to version 38.0.1.\nAuthentication and privilege requirements typically map to operator or administrative privileges capable of interacting with the Ironic API to manage node lifecycles, enroll hardware, and alter driver configurations.\nNetwork exposure is constrained to the OpenStack management network hosting the Ironic API service.\nThe step-by-step attack flow involves an actor enrolling a bare metal node or modifying its deploy interface to the autodetect option. Due to the implementation flaw, the state machine bypasses or fails to invoke the mandatory cleaning cycle that normally sanitizes local storage and resets firmware configurations between allocations.\nPost-exploitation impact includes potential data remanence on disks if nodes are subsequently provisioned to different tenants without prior manual intervention, leading to unauthorized data exposure across multi-tenant boundaries."
}