CVE-2026-90461
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 0.21%
- CWE
- CWE-923
- Published
- 2026-09-11
- Last modified
- 2026-09-14
Affected products
- OpenStack Ironic
- OpenStack Ironic
- OpenStack Ironic
- OpenStack Ironic
Weakness type
Related vulnerabilities
- CVE-2019-17440 — PAN-OS on PA-7000 Series: Improper restriction of communication to Log Forwarding Card (LFC) allows root access
- CVE-2026-34205 — Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode
- CVE-2017-3891 — In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default conf
- CVE-2023-28078 — Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A
- CVE-2025-61939 — Columbia Weather Systems MicroServer Improper Restriction of Communication Channel to Intended Endpoints
- CVE-2025-20261 — Cisco Integrated Management Controller Privilege Escalation Vulnerability
- CVE-2021-38487 — Potential Network Amplification and Information Exposure in RTI Connext Professional and Connext Micro
- CVE-2025-58742 — Insufficient Configuration Protections Enable Database Credential Interception in Milner ImageDirector Capture