What is CVE-2026-66138?
In OpenStack Ironic Python Agent up to version 11.6.0, a project-scoped user with manager role can achieve arbitrary code execution on a running agent via a maliciously crafted configuration, because the 'ntp_server' value is passed to a shell. This flaw allows remote code execution through crafted configuration files. Immediate patching or restricting configuration changes by unprivileged users is recommended.
Azərbaycanca: OpenStack Ironic Python Agent-də (11.6.0-a qədər versiyalarda) manager roluna malik layihə əhatəli istifadəçi, 'ntp_server' konfiqurasiya dəyərinin qabığa ötürülməsi səbəbindən işlək agent üzərində ixtiyari kod icra edə bilər. Bu boşluq zərərli konfiqurasiya faylı vasitəsilə uzaqdan kod icrasına yol açır. Təsirə məruz qalan sistemlərdə dərhal yamaq tətbiq etmək və ya təsdiqlənməmiş istifadəçilərin konfiqurasiya dəyişikliklərini məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
What mechanism allows arbitrary code execution in CVE-2026-66138 within OpenStack Ironic Python Agent?
The 'ntp_server' configuration value is passed directly to a shell on the running agent, enabling a project-scoped user with manager role to execute arbitrary code remotely through a malicious configuration file.
What immediate mitigation is recommended for CVE-2026-66138?
Immediate patching is recommended, or alternatively, restricting configuration changes by unprivileged users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.