Description
In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.
Published: 2026-08-14
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenStack Ironic prior to version 38.0.1 contains a defect in the autodetect deploy interface that prevents the automatic cleaning routine from executing immediately after a node is enrolled or its deploy interface is changed to autodetect. As a result, the node is left in a partially initialized state that can cause subsequent deployment or management operations to fail or behave unpredictably.

Affected Systems

All installations of OpenStack Ironic running a version earlier than 38.0.1 are affected, because the default autodetect deploy interface is used during node enrollment and interface changes in those releases. The issue applies regardless of deployment scale or environment.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the defect is triggered by authenticated actions such as node enrollment or changing a node's deploy interface; therefore the likely attack vector is internal and requires valid OpenStack credentials.

Generated by OpenCVE AI on August 22, 2026 at 10:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenStack Ironic to version 38.0.1 or later to apply the fixed cleaning logic.
  • For nodes that have been enrolled or had their deploy interface changed before the upgrade, manually run the ironic cleaning command or re‑enroll the node to ensure a clean state.
  • Monitor node states and cleaning status after the upgrade to verify that all nodes are fully prepared for deployment.

Generated by OpenCVE AI on August 22, 2026 at 10:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Autodetect Deploy Interface Failure Causes Incomplete Cleaning in OpenStack Ironic ironic: OpenStack Ironic: Autodetect deploy interface fails to run cleaning
Weaknesses CWE-367
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 15 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Autodetect Deploy Interface Failure Causes Incomplete Cleaning in OpenStack Ironic

Fri, 14 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.
First Time appeared Openstack
Openstack ironic
Weaknesses CWE-226
CPEs cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
Vendors & Products Openstack
Openstack ironic
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Openstack Ironic
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T15:38:11.060Z

Reserved: 2026-08-14T22:53:17.869Z

Link: CVE-2026-74250

cve-icon Vulnrichment

Updated: 2026-08-17T15:38:07.019Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-14T23:16:34.853

Modified: 2026-09-01T21:04:08.583

Link: CVE-2026-74250

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-14T22:53:18Z

Links: CVE-2026-74250 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T11:00:04Z

Weaknesses
  • CWE-226

    Sensitive Information in Resource Not Removed Before Reuse

  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition