Security Advisory

CVE-2026-90461

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-11 21:32:33
Last updated 2026-09-11 21:32:33
Assigner mitre
CVSS score 6.3
State PUBLISHED

Description

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.