VDB

CVE-2026-54423

CVE-2026-54423 PUBLISHED CVSS 8.2 HIGH

Reported by mitre · Published July 10, 2026

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

Risk Scores

CVSS 3.1
8.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H

Affected Products

VendorProductVersions
OpenStackIronic22.1.0, 30.0.0, 32.0.0
OpenStackIronic22.1.0, 30.0.0, 32.0.0
openstackironic22.1.0, 30.0.0, 32.0.0

Timeline

  • Jul 10, 2026 Coalition ESS Score
  • Jul 10, 2026 CVE Published
  • Jul 10, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Aug 28, 2026 Security Advisory
  • Aug 29, 2026 EPSS Score
  • Sep 4, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›