CVE-2026-42510: OSSA-2026-008: OpenStack Ironic: Command Injection in Ironic IPMI Console Implementations (CVE-2026-42510) - errata 1
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenStack Ironicto a version that resolves this vulnerability.Fixed in 35.0.1 - Configuration
Do not use the Ironic non-default configuration that enables a console interface allowing ipmitool execution; use the default/non-console configuration until upgraded to 35.0.1.
OpenStack Ironic ipmitool console interface (IPMI console implementations) ipmitool execution / console interface in non-default configuration = non-default console interface should not be used
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42510?
The severity of CVE-2026-42510 is considered moderate as it allows ipmitool execution in a non-default configuration.
How do I fix CVE-2026-42510?
To fix CVE-2026-42510, review and restrict the console interface settings in your OpenStack Ironic configuration.
Which versions of OpenStack Ironic are affected by CVE-2026-42510?
CVE-2026-42510 affects OpenStack Ironic versions up to and including 25.0.0.
What can an attacker achieve using CVE-2026-42510?
An attacker can potentially execute ipmitool commands through the console interface, leading to unauthorized system access.
Is there a patch available for CVE-2026-42510?
Yes, to mitigate CVE-2026-42510, ensure you upgrade OpenStack Ironic to a version beyond 25.0.0 where the issue is addressed.