Sensitive Credential Exposure in OpenStack Ironic Python Agent
CVE-2026-54422

5.5MEDIUM

Key Information:

Vendor

Openstack

Vendor
CVE Published:
24 July 2026

What is CVE-2026-54422?

In the OpenStack Ironic Python Agent version up to 11.5.0, there exists a vulnerability that could allow an attacker using a malicious boot container to extract sensitive credentials intended for downloading the container. This exposure could lead to unauthorized access and manipulation of deployment processes, posing a significant risk to the integrity and security of the system. Users of the affected version should take immediate measures to secure their configurations and apply necessary updates to mitigate the risk.

Affected Version(s)

Ironic Python Agent 10.2.0 < 10.2.3

Ironic Python Agent 11.0.0 < 11.2.1

Ironic Python Agent 11.3.0 < 11.5.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.