https://seclists.org/oss-sec/2026/q3/95: [OSSA-2026-025] Ironic: RBAC Bypass in IPMI Raw Command Execution (CVE-2026-54423)
Published Jul 8, 2026
·Updated
Affected Software
1 affected component
Openstack Ironic
Frequently Asked Questions
1
What is the severity of CVE-2026-54423?
CVE-2026-54423 has been classified as a critical severity vulnerability due to its potential for RBAC bypass.
2
How do I fix CVE-2026-54423?
To fix CVE-2026-54423, ensure that you apply the latest patches provided by OpenStack for Ironic.
3
What systems are affected by CVE-2026-54423?
CVE-2026-54423 affects instances of OpenStack Ironic that utilize the IPMI raw command functionality.
4
What type of vulnerability is CVE-2026-54423?
CVE-2026-54423 is an RBAC bypass vulnerability that allows unauthorized command execution.
5
When was CVE-2026-54423 published?
CVE-2026-54423 was published on July 08, 2026.