CVE-2026-54422
MEDIUMOpenstack Ironic Python Agent - Insufficiently Protected Credentials
Title source: ruleDescription
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
Scores
CVSS v3
5.5
EPSS
0.0012
EPSS Percentile
2.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-522
Status
published
Products (3)
OpenStack/Ironic Python Agent
10.2.0 - 10.2.3
OpenStack/Ironic Python Agent
11.0.0 - 11.2.1
OpenStack/Ironic Python Agent
11.3.0 - 11.5.1
Published
Jul 24, 2026
Tracked Since
Jul 24, 2026