CVE-2026-90461
MEDIUM
NVD
CVSS Score
6.3
Severity
MEDIUM
Published
Sep 11, 2026
Vendor
unknown
Description
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.