CyberRota Analysis
AI-GeneratedOpenStack Ironic versions up to 38.0.0 are vulnerable to a security flaw that can inadvertently transmit user credentials to an unintended remote host when configured for HTTP(S) Basic Authentication with Image Service. This exposure could lead to unauthorized access and compromise of sensitive information. Organizations utilizing OpenStack Ironic should prioritize remediation to mitigate potential credential theft risks.
CVE
CVE-2026-90461
Severity
MEDIUM
CVSS
6.3
EPSS
0.21%
Original NVD Description
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.