CVE-2026-66138

EUVD-2026-48476
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
mitreCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
openstackironic_python_agent
11.6.0
CNA
openstackironic_python_agent
11.3.0 ≤
𝑥
≤ 11.5.1
CNA
openstackironic_python_agent
11.0.0 ≤
𝑥
≤ 11.2.1
CNA
openstackironic_python_agent
6.0.0 ≤
𝑥
≤ 10.2.3
CNA
Debian logo
Debian Releases
Debian Product
Codename
ironic-python-agent
forky
vulnerable
sid
vulnerable
trixie
vulnerable