VYPR
High severity8.2NVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026

CVE-2026-54423

CVE-2026-54423

Description

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.