CVE-2026-54422
EUVD-2026-4847524.07.2026, 05:16
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openstack | ironic_python_agent | 10.2.0 ≤ 𝑥 < 10.2.3 | CNA |
| openstack | ironic_python_agent | 11.0.0 ≤ 𝑥 < 11.2.1 | CNA |
| openstack | ironic_python_agent | 11.3.0 ≤ 𝑥 < 11.5.1 | CNA |
Debian Releases
Common Weakness Enumeration