{"id":"CVE-2026-71201","published":"2026-08-05T07:16:39.813","lastModified":"2026-08-05T18:17:15.770","description":"In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.","cvssScore":5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","cwes":["CWE-863"],"vendors":[],"products":[],"references":[{"url":"https://bugs.launchpad.net/ironic/+bug/2162715","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/08/05/16","tags":[]},{"url":"https://bugs.launchpad.net/ironic/+bug/2162715","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}