CVE-2026-54423: Openstack Ironic
High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
Affected products
- Openstack Ironic: from 22.1.0, before 29.0.6 (fixed in 29.0.6); from 30.0.0, before 32.0.2 (fixed in 32.0.2); from 32.0.0, before 35.0.2 (fixed in 35.0.2); from 36.0.0, before 37.0.1 (fixed in 37.0.1)
Published 2026-07-10. Last modified 2026-07-10.