VDB
CVE-2026-54423
CVE-2026-54423
PUBLISHED
CVSS 8.2 HIGH
Reported by mitre · Published July 10, 2026
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
Risk Scores
CVSS 3.1
8.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| OpenStack | Ironic | 22.1.0, 30.0.0, 32.0.0 |
| OpenStack | Ironic | 22.1.0, 30.0.0, 32.0.0 |
| openstack | ironic | 22.1.0, 30.0.0, 32.0.0 |
Timeline
- Jul 10, 2026 Coalition ESS Score
- Jul 10, 2026 CVE Published
- Jul 10, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 Security Advisory
- Aug 29, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score