OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
AV:NAttack VectorAC:HAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:CScopeC:NConfidentialityI:HIntegrityA:NAvailabilityGet the full picture for CVE-2026-46447 and every CVE in our database. Create a free account — no credit card required.
Create Free Account