What is CVE-2026-54422?
CVE-2026-54422: In OpenStack Ironic Python Agent up to version 11.5.0, a malicious bootc container deployed via ironic-python-agent may extract the credentials used to download it. This vulnerability could allow unauthorized access to sensitive information, so applying system updates is recommended.
Azərbaycanca: CVE-2026-54422: OpenStack Ironic Python Agent-in 11.5.0 versiyasına qədər olan versiyalarında, ironic-python-agent vasitəsilə deploy edilən zərərli bootc container, onu yükləmək üçün istifadə olunan etimadnamələri çıxara bilər. Bu boşluqdan istifadə edən hücumçu həssas məlumatlara icazəsiz giriş əldə edə bilər, ona görə də sistem yeniləmələri tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of OpenStack Ironic Python Agent are affected by CVE-2026-54422?
CVE-2026-54422 affects OpenStack Ironic Python Agent versions up to 11.5.0.
What can an attacker gain by exploiting CVE-2026-54422?
By exploiting this vulnerability, an attacker can extract the credentials used to download the malicious bootc container, gaining unauthorized access to sensitive information.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.