Review reviewHigh

CVE-2026-42997

OpenStack Ironic, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.

CVSS
7.7
EPSS
0.43%
35.7% percentile
CISA KEV
Not listed
Published
2026.05.06
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.43%
Technical severityCVSS 7.7

Vulnerability overview

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.

Affected product and versions

Product
OpenStack Ironic, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2
Affected versions
>= 17.0.0 < 26.1.6, >= 27.0.0 < 29.0.5, >= 30.0.0 < 32.0.1, >= 33.0.0 < 35.0.1
Fixed versions
26.1.6, 29.0.5, 32.0.1, 35.0.1

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that OpenStack Ironic, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE
CWE-201, CWE-669
CVE-2026-42997 — OpenStack Ironic, Red Hat OpenShift Container Platform 4, Red Hat OpenStack Platform 16.2 | SECUFOCUS NOW