An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntpserver is passed to a shell.
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntpserver is passed to a shell.
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
======================================================= OSSA-2026-027: Command execution via unsanitized config =======================================================
:Date: July 23, 2026 :CVE: CVE-2026-pending
Affects ~~~~~~~ Description ~~~~~~~~~~~ Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io Security Team reported a vulnerability in Ironic-Python-Agent's (IPAs) time syncing code.
The value of the ntpserver configuration option is inserted into a shell command without sanitization. This command is run as root very early in the IPA startup flow, allowing an attacker to run arbitrary commands as root. set via kernel command line using Ironic, or passing the parameters via mDNS responder for mDNS enabled installation. For the most common, and highest as node.owner may be able to trigger this vulnerability.
Patches ~~~~~~~ - https://review.opendev.org/998486 (2026.2/hibiscus (development)) - https://review.opendev.org/998488 (2026.1/gazpacho) - https://review.opendev.org/998489 (2025.2/flamingo) - https://review.opendev.org/998490 (2025.1/epoxy) - https://review.opendev.org/998491 (2024.1/caracal (unmaintained)) - https://review.opendev.org/998492 (2023.1/antelope (unmaintained)) - https://review.opendev.org/998487 (bugfix/11.6) - https://review.opendev.org/998482 (bugfix/11.4) - https://review.opendev.org/998483 (bugfix/11.3)
Credits ~~~~~~~ - Dmitry Tantsur from Red Hat - Tuomo Tanskanen from Ericsson Software Technology
References ~~~~~~~~~~ - https://launchpad.net/bugs/2160050 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-pending
Notes ~~~~~ - A CVE assignment is pending from MITRE. This advisory will be updated when the CVE is assigned. - Branches 2024.1/caracal and 2023.1/antelope are unmaintained and patches are provided as a courtesy. - Bugfix branches will receive patches in git but will not receive an updated release. - While root access to a node running an Ironic workflow has security implications for that specific node, there is no known method for turning node ramdisk shell access into a full compromise of the Ironic service.
-- Goutham Pacha Ravi OpenStack Vulnerability Management Team https://security.openstack.org/vmt.html