MEDIUMVulnerability

CVE-2026-90461

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

Properties

severity
MEDIUM
score
6.3
cve_id
CVE-2026-90461
signal_observed_at
2026-09-23T04:35:40+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
published_at
2026-09-11T22:16:48.403
last_modified
2026-09-22T19:56:19.073

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Restriction of Communication Channel to Intended Endpoints

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90461 — Ninja Signal Threat Intelligence | Ninja Signal