Upstream information

CVE-2026-48681 at MITRE

Description

OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v3 Scores
CVSS detail CNA (MITRE) National Vulnerability Database SUSE
Base Score 5.9 8.1 5.9
Vector CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector Network Network Network
Attack Complexity High Low High
Privileges Required High Low High
User Interaction None None None
Scope Unchanged Unchanged Unchanged
Confidentiality Impact High High High
Integrity Impact High High High
Availability Impact None None None
CVSSv3 Version 3.1 3.1 3.1
SUSE Bugzilla entry: 1268089 [NEW]

No SUSE Security Announcements cross referenced.


SUSE Timeline for this CVE

CVE page created: Wed Jun 3 19:32:32 2026
CVE page last modified: Thu Jun 11 13:32:31 2026