CVE-2026-54423
OpenStack Ironic
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
- CVSS
- 8.2
- EPSS
- 0.30% 22.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.10