Arbitrary Code Execution Vulnerability in OpenStack Ironic Python Agent
CVE-2026-66138
7.2HIGH
What is CVE-2026-66138?
A vulnerability in OpenStack's Ironic Python Agent through version 11.6.0 allows a project-scoped user with the manager role to execute arbitrary code on a running instance. This occurs when the ntp_server value is improperly passed to a shell. By crafting a malicious configuration, an attacker can exploit this vulnerability, potentially leading to unauthorized actions on the system. It is crucial for users of affected versions to apply recommended security updates and to follow best practices to mitigate risks.
Affected Version(s)
Ironic Python Agent 11.6.0
Ironic Python Agent 11.3.0 <= 11.5.1
Ironic Python Agent 11.0.0 <= 11.2.1
