CVE-2026-54423
published 2026-07-10CVE-2026-54423: In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to…
PriorityP349high8.2CVSS 3.1
AVNACLPRHUINSCCLILAH
EPSS
0.52%
40.3th percentile
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | ironic | >= 22.1.0 < 29.0.6 | 29.0.6 |
| openstack | ironic | >= 30.0.0 < 32.0.2 | 32.0.2 |
| openstack | ironic | >= 32.0.0 < 35.0.2 | 35.0.2 |
| openstack | ironic | >= 36.0.0 < 37.0.1 | 37.0.1 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-ironic: openstack-ironic: Arbitrary IPMI command execution via send_raw deployment step
vendor_redhat·2026-07-08·CVSS 6.5
CVE-2026-54423 [MEDIUM] CWE-862 openstack-ironic: openstack-ironic: Arbitrary IPMI command execution via send_raw deployment step
openstack-ironic: openstack-ironic: Arbitrary IPMI command execution via send_raw deployment step
A malicious user with access to deploy a node directly via Ironic can specify the IPMI send_raw deployment step with a malicious payload and send commands to that nodes' BMC. IPMI send_raw capability is exposed multiple ways, including via VendorPassthru interfaces (restricted to system admin) and other step based flows such as cleaning or servicing. This also means any malicious user with the ability to initiate manual cleaning and servicing flows with arbitrary steps can also execute this vulnerability.
Statement: The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate. While the IPMI send_raw functionality lacks a blocklist in certain step-based provi
GHSA
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node,
ghsa_unreviewed·2026-07-10
CVE-2026-54423 [HIGH] CWE-424 In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node,
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
No detection rules found.
No public exploits indexed.
2026-07-10
Published