High severity7.2NVD Advisory· Published Jul 24, 2026· Updated Jul 30, 2026
CVE-2026-66138
CVE-2026-66138
Description
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.
Affected products
2<=11.6.0+ 1 more
- (no CPE)range: <=11.6.0
- (no CPE)range: <=11.6.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.