CVE-2026-90461
Received Received - Intake

OpenStack Ironic HTTP Basic Auth Credential Leak

Vulnerability report for CVE-2026-90461, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: MITRE

Description

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openstack ironic to 38.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-923 The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenStack Ironic versions up to 38.0.0 may inadvertently transmit credentials to an unintended remote host when the Image Service uses HTTP(S) Basic Authentication. This occurs due to improper handling of authentication requests.

Detection Guidance

This vulnerability involves OpenStack Ironic sending credentials to an unexpected host when Image Service uses HTTP(S) Basic Authentication. Detection requires checking Ironic configuration files for Image Service settings and monitoring network traffic for unexpected credential transmissions. Review Ironic logs and configuration files like /etc/ironic/ironic.conf for Image Service HTTP(S) Basic Authentication settings. Use network monitoring tools like tcpdump or Wireshark to inspect traffic for credential leaks during image transfers.

Impact Analysis

An attacker could intercept the credentials sent to the wrong host, potentially gaining unauthorized access to systems or data. This may lead to data breaches, unauthorized operations, or further exploitation within the OpenStack environment.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by exposing sensitive credentials and potentially leading to unauthorized access to personal or health data. Organizations may face penalties or legal consequences for failing to protect such data.

Mitigation Strategies

Disable HTTP(S) Basic Authentication for Image Service in OpenStack Ironic configuration. Review network traffic for unexpected credential transmissions. Update OpenStack Ironic to a version beyond 38.0.0 if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90461. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart