
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42510 is a command injection vulnerability in OpenStack Ironic's IPMI console implementations, classified as "Inclusion of Functionality from Untrusted Control Sphere" (CWE-829). Reported by Dmitry Tantsur and Tuomo Tanskanen from the Metal3.io Security Team, it affects Ironic versions >=4.3.0 <26.1.6, >=27.0.0 <29.0.5, >=30.0.0 <32.0.1, and >=33.0.0 <35.0.1 (i.e., through 25.0.0 per pip package versioning). The vulnerability was originally disclosed on April 27, 2026, with CVE assignment on April 29, 2026, and published to NVD on April 28, 2026. It carries a CVSS v3.1 base score of 6.6 (Medium/Moderate), requiring high privileges and high attack complexity (GitHub Advisory, oss-security).
The vulnerability exists in Ironic's IPMI console backends (ipmitool-shellinabox and ipmitool-socat), which are non-default console interfaces. A project manager holding the node.owner role can inject arbitrary commands that the Ironic conductor executes upon console activation, constituting a command injection via an untrusted control sphere (CWE-829). Exploitation requires that an operator has explicitly enabled [conductor]/enabled_console_interfaces to include either ipmitool-shellinabox or ipmitool-socat — neither is enabled by default. Patches are available across multiple release branches via OpenDev review (oss-security, GitHub Advisory).
A high-privileged attacker (project manager with node.owner role) who successfully exploits this vulnerability can inject and execute arbitrary ipmitool commands on the Ironic conductor host. This results in high impact to confidentiality, integrity, and availability of the affected system, potentially enabling full control over bare-metal nodes managed by Ironic, including unauthorized power cycling, firmware manipulation, or data exfiltration from managed hardware (GitHub Advisory, oss-security).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.027% (8th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for high privileges (node.owner role) and a non-default configuration enabling IPMI console interfaces (GitHub Advisory, Feedly).
[conductor]/enabled_console_interfaces set to ipmitool-shellinabox or ipmitool-socat.node.owner or project manager role within the OpenStack project.openstack baremetal node list).ipmitool upon console activation.openstack baremetal node console enable <node>), causing the conductor to execute the injected command.ipmitool command executions in Ironic conductor logs (/var/log/ironic/ironic-conductor.log), particularly commands not matching standard console operations; console enable/disable events for nodes triggered by unexpected users.ipmitool wrappers.ipmitool-shellinabox or ipmitool-socat in [conductor]/enabled_console_interfaces in ironic.conf, combined with recent console activation events for nodes owned by non-administrative project managers (oss-security).Organizations should upgrade OpenStack Ironic to a patched version: >=26.1.6 (2024.2/dalmatian), >=29.0.5 (2025.1/epoxy), >=32.0.1 (2025.2/flamingo), or >=35.0.1 (2026.1/gazpacho). Patches for unmaintained branches (antelope, caracal) are also available as a courtesy via OpenDev. As an immediate workaround, disable the vulnerable console interfaces by removing ipmitool-shellinabox and ipmitool-socat from [conductor]/enabled_console_interfaces in ironic.conf; note that ipmitool-shellinabox is already scheduled for removal due to lack of security support. Additionally, restrict network access to Ironic administrative interfaces and enforce least-privilege access controls (oss-security, GitHub Advisory).
The OpenStack Vulnerability Management Team published OSSA-2026-008 and coordinated disclosure through the oss-security mailing list. The ipmitool-shellinabox console interface was noted as already scheduled for removal from Ironic due to lack of security support, and security-sensitive operators were strongly encouraged to stop using it immediately. The vulnerability was discussed briefly on Bluesky (infosec.skyfleet.blue) and noted in CVE tracking feeds shortly after disclosure (oss-security, GitHub Advisory).
Fix availability across major Linux distributions and their releases.
bookworm
ironic: 1:21.1.0-3+deb12u1
sid
ironic: 1:35.0.1-1
trixie
ironic: 1:29.0.5-0+deb13u1
bionic (esm-apps)
ironic
devel
ironic
focal (esm-apps)
ironic
jammy
ironic
jammy (esm-apps)
ironic
noble
ironic
noble (esm-apps)
ironic
resolute
ironic
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."