https://seclists.org/oss-sec/2026/q2/233: [OSSA-2026-008] Ironic: Command Injection in IPMI Console Implementations (CVE pending)
Published Apr 27, 2026
·Updated
Affected Software
1 affected component
Openstack Ironic>=4.3.0<26.1.6, >=27.0.0<29.0.5, >=30.0.0<32.0.1, >=33.0.0<35.0.1
Frequently Asked Questions
1
What is the severity of OSSA-2026-008?
The severity of OSSA-2026-008 is currently not classified as it awaits a CVE assignment.
2
How do I fix OSSA-2026-008?
To mitigate OSSA-2026-008, users should upgrade their OpenStack Ironic installations to the latest version that addresses the vulnerability.
3
What does OSSA-2026-008 affect?
OSSA-2026-008 affects OpenStack Ironic versions from 4.3.0 up to but not including 26.1.
4
What kind of vulnerability is OSSA-2026-008?
OSSA-2026-008 is a command injection vulnerability found in the IPMI console implementations of OpenStack Ironic.
5
When was OSSA-2026-008 published?
OSSA-2026-008 was published on April 27, 2026.