AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-54423

HIGH · CVSS 8.2 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

OpenStack Ironic versions prior to 37.0.1 are vulnerable to unauthorized access through the IPMI management interface, allowing users to exploit the send_raw step to execute arbitrary IPMI commands on nodes. This vulnerability can lead to unauthorized control over hardware management functions, posing significant risks to system integrity and availability. Organizations using OpenStack Ironic should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-54423
Severity
HIGH
CVSS
8.2
EPSS
0.30%

Original NVD Description

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.