CVE-2026-42510: Openstack Ironic
High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
Affected products
- Openstack Ironic: from 4.3.0, before 26.1.6 (fixed in 26.1.6); from 27.0.0, before 29.0.5 (fixed in 29.0.5); from 30.0.0, before 32.0.1 (fixed in 32.0.1); from 33.0.0, before 35.0.1 (fixed in 35.0.1)
Published 2026-04-28. Last modified 2026-08-20.