UNKNOWN OpenStack
CVE-2026-66138
OSSA-2026-027: Command execution via unsanitized config
Dmitry Tantsur (Red Hat) and Tuomo Tanskanen (Ericsson Software Technology) from the Metal3.io Security Team reported a vulnerability in Ironic-Python-Agent’s (IPAs) time syncing code. The value of the ntp_server configuration option is inserted into a shell command without sanitization. This command is run as root very early in the IPA startup flow, allowing an attacker to run arbitrary commands as root. This value can be set in three ways; directly in an operator-created ramdisk, set via kerne
Affected Products
- Ironic-python-agent: >=6.0.0 <10.2.3, >=11.0.0 <11.2.1, >=11.3.0 <11.5.1, ==11.6.0
- CVE-2026-66138
References
- https://security.openstack.org/ossa/OSSA-2026-027.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-66138
This unknown severity vulnerability was published on 2026-07-23 via OpenStack. Affected: Ironic-python-agent: >=6.0.0 <10.2.3, >=11.0.0 <11.2.1, >=11.3.0 <11.5.1, ==11.6.0, CVE-2026-66138.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.