Arbitrary Code Execution Vulnerability in OpenStack Ironic Python Agent
CVE-2026-66138

7.2HIGH

Key Information:

Vendor

Openstack

Vendor
CVE Published:
24 July 2026

What is CVE-2026-66138?

A vulnerability in OpenStack's Ironic Python Agent through version 11.6.0 allows a project-scoped user with the manager role to execute arbitrary code on a running instance. This occurs when the ntp_server value is improperly passed to a shell. By crafting a malicious configuration, an attacker can exploit this vulnerability, potentially leading to unauthorized actions on the system. It is crucial for users of affected versions to apply recommended security updates and to follow best practices to mitigate risks.

Affected Version(s)

Ironic Python Agent 11.6.0

Ironic Python Agent 11.3.0 <= 11.5.1

Ironic Python Agent 11.0.0 <= 11.2.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.