Where
-Infinity
0
Severity
8.5
OS Command Injection
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.

First published (updated )
Severity
7.2
OS Command Injection
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntpserver is passed to a shell.

1 / 2
Source: Red Hat
First published (updated )
Severity
7

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntpserver is passed to a shell.

First published (updated )
Severity
5.5
AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

First published (updated )

======================================================= OSSA-2026-027: Command execution via unsanitized config =======================================================

:Date: July 23, 2026 :CVE: CVE-2026-pending

Affects ~~~~~~~ Description ~~~~~~~~~~~ Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io Security Team reported a vulnerability in Ironic-Python-Agent's (IPAs) time syncing code.

The value of the ntpserver configuration option is inserted into a shell command without sanitization. This command is run as root very early in the IPA startup flow, allowing an attacker to run arbitrary commands as root. set via kernel command line using Ironic, or passing the parameters via mDNS responder for mDNS enabled installation. For the most common, and highest as node.owner may be able to trigger this vulnerability.

Patches ~~~~~~~ - https://review.opendev.org/998486 (2026.2/hibiscus (development)) - https://review.opendev.org/998488 (2026.1/gazpacho) - https://review.opendev.org/998489 (2025.2/flamingo) - https://review.opendev.org/998490 (2025.1/epoxy) - https://review.opendev.org/998491 (2024.1/caracal (unmaintained)) - https://review.opendev.org/998492 (2023.1/antelope (unmaintained)) - https://review.opendev.org/998487 (bugfix/11.6) - https://review.opendev.org/998482 (bugfix/11.4) - https://review.opendev.org/998483 (bugfix/11.3)

Credits ~~~~~~~ - Dmitry Tantsur from Red Hat - Tuomo Tanskanen from Ericsson Software Technology

References ~~~~~~~~~~ - https://launchpad.net/bugs/2160050 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending

Notes ~~~~~ - A CVE assignment is pending from MITRE. This advisory will be updated when the CVE is assigned. - Branches 2024.1/caracal and 2023.1/antelope are unmaintained and patches are provided as a courtesy. - Bugfix branches will receive patches in git but will not receive an updated release. - While root access to a node running an Ironic workflow has security implications for that specific node, there is no known method for turning node ramdisk shell access into a full compromise of the Ironic service.

-- Goutham Pacha Ravi OpenStack Vulnerability Management Team https://security.openstack.org/vmt.html

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203