CVE-2026-66138

Summary

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.

Affected Software

VendorProductVersion RangeStatus
OpenStackIronic Python Agent11.6.0affected
OpenStackIronic Python Agent11.3.0 <= 11.5.1affected
OpenStackIronic Python Agent11.0.0 <= 11.2.1affected
OpenStackIronic Python Agent6.0.0 <= 10.2.3affected

Weaknesses

  • CWE-78: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

CVE Program Container

Additional References

References