CVE-2026-66138: [OSSA-2026-027] OpenStack Ironic Python Agent: Command execution via unsanitized config (CVE-2026-66138)
Published Jul 24, 2026
·Updated
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntpserver is passed to a shell.
Affected Software
1 affected component
Openstack Ironic Python Agent<=11.6.0
Event History
Jul 24, 2026
CVE Published
via MITRE·03:53 AM
Data Sourced
via MITRE·03:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66138?
CVE-2026-66138 has a severity rating of high, with a score of 7.2.
2
What type of vulnerability is CVE-2026-66138?
CVE-2026-66138 is an OS Command Injection vulnerability.
3
Who is affected by CVE-2026-66138?
A project-scoped user with the manager role in OpenStack Ironic Python Agent is affected by CVE-2026-66138.
4
How can CVE-2026-66138 be exploited?
CVE-2026-66138 can be exploited through a maliciously constructed configuration, allowing for arbitrary code execution.
5
How do I fix CVE-2026-66138?
To fix CVE-2026-66138, update to the patched version of OpenStack Ironic Python Agent beyond 11.6.0.