CyberRota Analysis
AI-GeneratedThe vulnerability in OpenStack Ironic Python Agent allows a malicious boot container to potentially extract credentials used for its deployment, posing a risk of unauthorized access to sensitive information. Organizations utilizing OpenStack Ironic versions up to 11.5.0 should prioritize patching this issue to mitigate the risk of credential exposure and maintain the integrity of their cloud environments.
CVE
CVE-2026-54422
Severity
MEDIUM
CVSS
5.5
EPSS
0.12%
Original NVD Description
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.