UNKNOWN OpenStack
CVE-2026-54423
OSSA-2026-025: RBAC Bypass in IPMI Raw Command Execution
Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) of the Metal3.io Security Team descovered a vulnerability around IPMI management_interface. A malicious user with access to deploy a node directly via Ironic can specify the IPMI send_raw deployment step with a malicious payload and send commands to that nodes’ BMC. IPMI send_raw capability is exposed multiple ways, including via our VendorPassthru interfaces (restricted to system admin) and other step based flows such a
Affected Products
- Ironic: >=22.1.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, >=36.0.0 <37.0.1
- CVE-2026-54423
References
- https://security.openstack.org/ossa/OSSA-2026-025.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-54423
This unknown severity vulnerability was published on 2026-07-08 via OpenStack. Affected: Ironic: >=22.1.0 <29.0.6, >=30.0.0 <32.0.2, >=33.0.0 <35.0.2, >=36.0.0 <37.0.1, CVE-2026-54423.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.