Security Advisory

CVE-2026-54423

8.2
HIGH

Vulnerability Description

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
Published Date July 10, 2026
Official Source NIST NVD Advisory