CVE-2026-42510

OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

Description

OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.

Metrics

Severity
high
no public PoC known
7.2
Source: nvd-v3
45.1 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.6 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-13 15:02 UTC
CWE-829

Weakness classes (CWE)

  • CWE-829Base

    Inclusion of Functionality from Untrusted Control Sphere

    The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-20 01:16 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/08/19/6

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • openstack

    ironic27.0.0 – 29.0.5

  • openstack

    ironic30.0.0 – 32.0.1

  • openstack

    ironic33.0.0 – 35.0.1

  • openstack

    ironic4.3.0 – 26.1.6

References & sources

IDCVE-2026-42510