UNKNOWN OpenStack

CVE-2026-66138

OSSA-2026-027: Command execution via unsanitized config

Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io Security Team reported a vulnerability in Ironic-Python-Agent’s (IPAs) time syncing code. The value of the ntp_server configuration option is inserted into a shell command without sanitization. This command is run as root very early in the IPA startup flow, allowing an attacker to run arbitrary commands as root. This value can be set in three ways; directly in an operator-created ramdisk, set via kerne

Affected Products

References

Published: 2026-07-23 · Source: OpenStack · Feed updated: 2026-08-04
This unknown severity vulnerability was published on 2026-07-23 via OpenStack. Affected: Ironic-python-agent: >=6.0.0 <10.2.3, >=11.0.0 <11.2.1, >=11.3.0 <11.5.1, ==11.6.0, CVE-2026-66138.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.