CVE-2026-66138
Basic Information
| Severity | HIGH |
|---|---|
| Base Score | 7.2 |
| CNA | mitre |
| Published Date | 2026-07-23 23:53:12 UTC |
| Last Modified | 2026-07-23 23:53:12 UTC |
| CVE.org Link | https://www.cve.org/CVERecord?id=CVE-2026-66138 |
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-66138 |
Description
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.
Affected Products
| Vendor | Product |
|---|---|
| openstack | ironic python agent |