REDHAT-BUG-2506676: High severity Openstack Ironic Python Agent vulnerability
Published Jul 24, 2026
·Updated
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntpserver is passed to a shell.
Affected Software
1 affected component
Openstack Ironic Python Agent<=11.6.0
Event History
Jul 24, 2026
Data Sourced
via Red Hat·05:09 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be a project-scoped user with the manager role and must be able to supply a maliciously constructed configuration containing an ntp_server value.
2
What systems are exposed to code execution?
A running Ironic-Python-Agent is exposed when it processes the attacker-controlled ntp_server configuration. The issue is described as affecting OpenStack Ironic Python Agent through version 11.6.0.