SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-66138

HIGH · CVSS 7.2 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

OpenStack Ironic Python Agent versions up to 11.6.0 are vulnerable to arbitrary code execution due to improper handling of the `ntp_server` configuration value, which can be exploited by a project-scoped user with manager privileges. This vulnerability poses a significant risk as it allows attackers to execute arbitrary commands on the Ironic-Python-Agent, potentially compromising the entire environment. Organizations utilizing OpenStack Ironic should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66138
Severity
HIGH
CVSS
7.2
EPSS
0.42%

Original NVD Description

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.