MEDIUMVulnerability

CVE-2026-71201

In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.

Properties

severity
MEDIUM
score
5
epss_score
0.00188
cve_id
CVE-2026-71201
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
published_at
2026-08-05T07:16:39.813
last_modified
2026-09-09T16:03:22.897
epss_percentile
0.08574

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-71201 — Ninja Signal Threat Intelligence | Ninja Signal