CVE-2026-66138: [OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-66138)
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntpserver is passed to a shell.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenStack Ironic Python Agentto a version that resolves this vulnerability.Patch OSSA-2026-027
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66138?
CVE-2026-66138 has a severity rating of high, with a score of 7.2.
What type of vulnerability is CVE-2026-66138?
CVE-2026-66138 is an OS Command Injection vulnerability.
Who is affected by CVE-2026-66138?
A project-scoped user with the manager role in OpenStack Ironic Python Agent is affected by CVE-2026-66138.
How can CVE-2026-66138 be exploited?
CVE-2026-66138 can be exploited through a maliciously constructed configuration, allowing for arbitrary code execution.
How do I fix CVE-2026-66138?
To fix CVE-2026-66138, update to the patched version of OpenStack Ironic Python Agent beyond 11.6.0.