Description
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
Published: 2026-09-11
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Leakage
Action: Immediate Patch
AI Analysis

Impact

OpenStack Ironic versions up to 38.0.0 can transmit HTTP when the Image Service is configured to use these credentials. This flaw exposes the username and password to anyone who can observe the traffic to that host, potentially allowing attackers to gain unauthorized access to the image registry or other services protected by those credentials. The vulnerability impacts confidentiality by risking credential disclosure but does not enable remote code execution or direct system compromise.

Affected Systems

The affected product is OpenStack Ironic, all releases through version 38.0.0. The issue is present in any deployment that configures the Image Service to use HTTP or HTTPS Basic Authentication, regardless of other components.

Risk and Exploitability

The CVSS score of 6.3 categorizes this as a moderate-severity issue. The EPSS score is < 1%, and the CVE is not listed in CISA’s KEV catalog, indicating no known widespread exploitation at present. The likely attack vector is that an attacker controls or compromises the unexpected remote host and receives the transmitted credentials. Exploitation requires the configuration of the Image Service to use Basic Authentication and the presence of a remote host to capture the credentials; no elevation of privileges or code execution is involved. The risk is primarily in credential exposure and subsequent lateral movement or service compromise by the attacker.

Generated by OpenCVE AI on September 15, 2026 at 19:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest OpenStack Ironic release (above 38.0.0) or install the vendor patch that corrects the credential transmission behavior.
  • If upgrading is not immediately possible, remove or disable HTTP(S) Basic Authentication for the Image Service configuration and use alternative authentication mechanisms such as API tokens or key‑based access.
  • Verify no unintended credential trafficcapture tools and restrict outbound connections from Ironic nodes to authorized hosts only.

Generated by OpenCVE AI on September 15, 2026 at 19:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title ironic: OpenStack Ironic: Information disclosure via unexpected credential transmission
Weaknesses CWE-201
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
First Time appeared Openstack
Openstack ironic
Weaknesses CWE-923
CPEs cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:*
Vendors & Products Openstack
Openstack ironic
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Openstack Ironic
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:17:14.063Z

Reserved: 2026-09-11T21:32:33.385Z

Link: CVE-2026-90461

cve-icon Vulnrichment

Updated: 2026-09-14T14:56:57.722Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T22:16:48.403

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-90461

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T21:32:33Z

Links: CVE-2026-90461 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:15:16Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data

  • CWE-923

    Improper Restriction of Communication Channel to Intended Endpoints