CVE-2026-54422

Summary

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

Affected Software

VendorProductVersion RangeStatus
OpenStackIronic Python Agent10.2.0 < 10.2.3affected
OpenStackIronic Python Agent11.0.0 < 11.2.1affected
OpenStackIronic Python Agent11.3.0 < 11.5.1affected

Weaknesses

  • CWE-522: CWE-522 Insufficiently Protected Credentials

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References