CVE-2026-44916: [OSSA-2026-012] Ironic: mote Code Execution when Anaconda driver enabled (CVE-2026-44916)
Published May 8, 2026
·Updated
In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.
Affected Software
1 affected component
Openstack Ironic<35.0.2
Event History
May 8, 2026
CVE Published
via MITRE·06:38 AM
Data Sourced
via MITRE·06:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44916?
CVE-2026-44916 is considered a high-severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2026-44916?
To fix CVE-2026-44916, upgrade to a version of OpenStack Ironic that is beyond 35.x, where the vulnerability is resolved.
3
What are the impacts of CVE-2026-44916?
The impacts of CVE-2026-44916 include potential unauthorized access and execution of malicious code on affected systems.
4
Who is affected by CVE-2026-44916?
CVE-2026-44916 affects users of OpenStack Ironic versions up to and including 35.x.
5
What is the vulnerability type for CVE-2026-44916?
CVE-2026-44916 is a code injection vulnerability caused by the rendering of instance_info['ks_template'] without proper sandboxing.