{"id":"PYSEC-2026-2526","summary":"OpenStack Ironic has an Incorrect Resource Transfer Between Spheres","details":"An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or basic credentials configured for molds storage. The fixed versions are 26.1.6, 29.0.5, 32.0.1, and 35.0.1.","aliases":["CVE-2026-42997","GHSA-54w4-233h-x86g"],"modified":"2026-08-05T16:15:09.603502207Z","published":"2026-07-13T15:15:38.280049Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42997"},{"type":"PACKAGE","url":"https://github.com/openstack/ironic-python-agent"},{"type":"WEB","url":"https://security.openstack.org/ossa/OSSA-2026-010.html"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/05/05/10"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/05/05/10"},{"type":"PACKAGE","url":"https://pypi.org/project/ironic-python-agent"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-54w4-233h-x86g"}],"affected":[{"package":{"name":"ironic-python-agent","ecosystem":"PyPI","purl":"pkg:pypi/ironic-python-agent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.1.6"},{"introduced":"27.0.0"},{"fixed":"29.0.5"},{"introduced":"30.0.0"},{"fixed":"32.0.1"},{"introduced":"33.0.0"},{"fixed":"35.0.1"}]}],"versions":["0.0.1","1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.1.0","1.2.0","1.2.1","1.2.2","1.2.3","1.3.0","1.4.0","1.5.0","1.5.1","1.5.2","10.0.0","10.1.0","10.2.0","10.2.1","10.2.2","10.2.3","11.0.0","11.1.0","11.2.0","11.3.0","11.4.0","11.5.0","11.6.0","12.0.0","2.0.0","2.0.1","2.0.2","2.0.3","2.1.0","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","3.0.0","3.1.0","3.2.0","3.2.1","3.2.2","3.2.3","3.2.4","3.3.0","3.3.1","3.3.2","3.3.3","3.4.0","3.5.0","3.6.0","3.6.1","3.6.2","3.6.3","3.6.4","3.6.5","3.7.0","4.0.0","5.0.0","5.0.1","5.0.2","5.0.3","5.0.4","6.0.0","6.1.0","6.1.1","6.1.2","6.1.3","6.2.0","6.3.0","6.4.0","6.4.1","6.4.2","6.4.3","6.4.4","6.5.0","6.6.0","7.0.0","7.0.1","7.0.2","7.1.0","8.0.0","8.1.0","8.2.0","8.2.1","8.2.2","8.2.3","8.3.0","8.4.0","8.5.0","8.5.1","8.5.2","8.5.3","8.6.0","9.0.0","9.1.0","9.1.1","9.10.0","9.11.0","9.11.1","9.11.2","9.11.3","9.12.0","9.13.0","9.14.0","9.14.1","9.2.0","9.3.0","9.4.0","9.4.1","9.4.2","9.4.3","9.5.0","9.6.0","9.7.0","9.7.1","9.7.2","9.7.3","9.8.0","9.9.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/ironic-python-agent/PYSEC-2026-2526.yaml"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}