CVE-2026-66138

Basic Information

Severity HIGH
Base Score 7.2
CNA mitre
Published Date 2026-07-23 23:53:12 UTC
Last Modified 2026-07-23 23:53:12 UTC
CVE.org Link https://www.cve.org/CVERecord?id=CVE-2026-66138
NVD https://nvd.nist.gov/vuln/detail/CVE-2026-66138

Description

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.

Affected Products

Vendor Product
openstack ironic python agent