CVE-2026-90461

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

  • Published Sep 11, 2026
  • CVSS 6.3 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-90461 at the National Vulnerability Database