CVE-2026-42510
published 2026-04-28CVE-2026-42510: OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
PriorityP340medium6.6CVSS 3.1
AVNACHPRHUINSUCHIHAH
EPSS
0.57%
43.2th percentile
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | ironic | 0 – 25.0.0 | — |
| openstack | ironic | 27.0.0 – 29.0.5 | — |
| openstack | ironic | 30.0.0 – 32.0.1 | — |
| openstack | ironic | 33.0.0 – 35.0.1 | — |
| openstack | ironic | 4.3.0 – 26.1.6 | — |
CVSS provenance
nvdv3.16.6MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
ghsa·2026-04-28
CVE-2026-42510 [MEDIUM] CWE-829 OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
OpenStack Ironic through 25.0.0 allows ipmitool execution in a non-default configuration that has a console interface.
VulDB
OpenStack Ironic up to 25.0.0 ipmitool inclusion of functionality from untrusted control sphere
vuldb·2026-04-28·CVSS 6.6
CVE-2026-42510 [MEDIUM] OpenStack Ironic up to 25.0.0 ipmitool inclusion of functionality from untrusted control sphere
A vulnerability described as critical has been identified in OpenStack Ironic up to 25.0.0. This issue affects some unknown processing of the component ipmitool. Such manipulation leads to inclusion of functionality from untrusted control sphere.
This vulnerability is traded as CVE-2026-42510. The attack may be launched remotely. There is no exploit available.
Red Hat
OpenStack Ironic: ipmitool: OpenStack Ironic: Arbitrary Code Execution via Remote Hardware Management
vendor_redhat·2026-04-28·CVSS 6.6
CVE-2026-42510 [MEDIUM] CWE-78 OpenStack Ironic: ipmitool: OpenStack Ironic: Arbitrary Code Execution via Remote Hardware Management
OpenStack Ironic: ipmitool: OpenStack Ironic: Arbitrary Code Execution via Remote Hardware Management
A flaw was found in OpenStack Ironic. When configured with a console interface in a non-default setup, this vulnerability allows an attacker to execute `ipmitool` commands. This unauthorized execution can lead to remote management of the underlying hardware, potentially resulting in arbitrary code execution, privilege escalation, and complete control over the affected system.
Mitigation: To mitigate this issue, avoid enabling the console interface in OpenStack Ironic if it is not strictly required for your operational needs. If the console interface is enabled, ensure that access to the OpenStack Ironic service is restricted to trusted administrative networks to prevent unauthorized `ipm
No detection rules found.
No public exploits indexed.
2026-04-28
Published