CVE-2026-74250
Received Received - Intake

OpenStack Ironic Autodetect Deploy Interface Cleaning Failure

Vulnerability report for CVE-2026-74250, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: MITRE

Description

In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-15
AI Q&A
2026-08-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openstack ironic to 38.0.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-226 The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in OpenStack Ironic before 38.0.1 involves the autodetect deploy interface failing to run cleaning immediately after enrollment or when switching to this interface. This could leave systems in an inconsistent state.

Impact Analysis

The failure to clean systems properly may lead to residual data or misconfigured deployments, potentially causing deployment failures or security risks in environments using OpenStack Ironic.

Mitigation Strategies

Upgrade OpenStack Ironic to version 38.0.1 or later to address the issue with the autodetect deploy interface failing to run cleaning after enrollment or interface changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74250. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart