CVE-2026-71201

Description

A flaw was found in OpenStack Ironic. A project reader can exploit this vulnerability by sending a specially crafted request to the Ironic service. This allows the reader to access Portgroups that are assigned to Nodes belonging to or leased by other projects, leading to unauthorized information disclosure.

Statement

This flaw has a moderate impact as OpenStack Ironic contains an authorization flaw in the Portgroups listing API. When a project-scoped reader lists portgroups by shard name, the service fails to apply the per-project ownership filter that it correctly applies on other listing paths, allowing the reader to enumerate portgroups belonging to nodes owned or leased by other projects. Exploitation requires valid project-reader credentials and knowledge of a target shard name, and discloses only portgroup metadata (no modification or availability impact), so the severity is limited to information disclosure across project boundaries. Red Hat OpenShift's baremetal (metal3) deployment runs Ironic as a single-tenant control-plane service and does not expose the multi-project reader RBAC path required for exploitation.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5N/A5
Attack VectorNetworkN/ANetwork
Attack ComplexityLowN/ALow
Privileges RequiredLowN/ALow
User InteractionNoneN/ANone
ScopeChangedN/AChanged
ConfidentialityLowN/ALow
Integrity ImpactNoneN/ANone
Availability ImpactNoneN/ANone

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

cve.org: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Understanding the Weakness (CWE)

Access Control

Technical Impact: Bypass Protection Mechanism

Access control checks for specific user data or functionality can be bypassed.

Access Control

Technical Impact: Gain Privileges or Assume Identity

Horizontal escalation of privilege is possible (one user can view/modify information of another user).

Access Control

Technical Impact: Gain Privileges or Assume Identity

Vertical escalation of privilege is possible if the user-controlled key is actually a flag that indicates administrator status, allowing the attacker to gain administrative access.

Frequently Asked Questions

Want to get errata notifications? Sign up here.