CVE-2026-74250: CWE-226 Sensitive Information in Resource Not Removed Before Reuse in OpenStack Ironic
In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.
AI Analysis
Technical Summary
This vulnerability (CWE-226) affects OpenStack Ironic versions prior to 38.0.1. The issue occurs because the autodetect deploy interface may not trigger the cleaning process immediately after a node is enrolled or when the deploy interface is changed to autodetect. As a result, sensitive information from previous deployments may remain on the node, potentially exposing it to unauthorized access. The CVSS 3.1 base score is 6.3 (medium severity), reflecting network attack vector, high attack complexity, low privileges required, no user interaction, and high confidentiality impact without integrity or availability impact.
Potential Impact
Sensitive information from previous deployments may remain on hardware nodes due to failure to clean immediately after enrollment or interface change. This could lead to unauthorized disclosure of sensitive data. There is no indication of integrity or availability impact. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch link is provided and remediation level is null, users should monitor OpenStack advisories for updates. Until a fix is available, avoid using the autodetect deploy interface immediately after enrollment or interface changes, or implement manual cleaning procedures to ensure sensitive data is removed.
CVE-2026-74250: CWE-226 Sensitive Information in Resource Not Removed Before Reuse in OpenStack Ironic
Description
In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.
CVSS v3.1
Score 6.3medium
Affected software
OpenStack
Ironic
pkg:github/openstack/ironicRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-226) affects OpenStack Ironic versions prior to 38.0.1. The issue occurs because the autodetect deploy interface may not trigger the cleaning process immediately after a node is enrolled or when the deploy interface is changed to autodetect. As a result, sensitive information from previous deployments may remain on the node, potentially exposing it to unauthorized access. The CVSS 3.1 base score is 6.3 (medium severity), reflecting network attack vector, high attack complexity, low privileges required, no user interaction, and high confidentiality impact without integrity or availability impact.
Potential Impact
Sensitive information from previous deployments may remain on hardware nodes due to failure to clean immediately after enrollment or interface change. This could lead to unauthorized disclosure of sensitive data. There is no indication of integrity or availability impact. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch link is provided and remediation level is null, users should monitor OpenStack advisories for updates. Until a fix is available, avoid using the autodetect deploy interface immediately after enrollment or interface changes, or implement manual cleaning procedures to ensure sensitive data is removed.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-08-14T22:53:17.869Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7f9d48bf8831d539dc2e16
Added to database: 08/14/2026, 22:57:12 UTC
Last enriched: 08/22/2026, 13:23:25 UTC
Last updated: 09/29/2026, 18:13:09 UTC
Views: 49
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.