Authentication and TLS Vulnerability in BMCtest by OpenShift Metal3
CVE-2026-71568
5.3MEDIUM
What is CVE-2026-71568?
BMCtest by OpenShift Metal3 is vulnerable as Ironic can be initiated without proper authentication and TLS protection during tests. This flaw requires an attacker to exploit a narrow timing window, making it complex to execute successfully. The lack of adequate safeguards increases the risk of unauthorized access and potential data exposure.
Affected Version(s)
bmctest 0 <= 9ddd432
bmctest 153aefb
