SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-54422

MEDIUM · CVSS 5.5 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

The vulnerability in OpenStack Ironic Python Agent allows a malicious boot container to potentially extract credentials used for its deployment, posing a risk of unauthorized access to sensitive information. Organizations utilizing OpenStack Ironic versions up to 11.5.0 should prioritize patching this issue to mitigate the risk of credential exposure and maintain the integrity of their cloud environments.

CVE
CVE-2026-54422
Severity
MEDIUM
CVSS
5.5
EPSS
0.12%

Original NVD Description

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.