CVE-2026-54422 Details
Description
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
A vulnerability exists in OpenStack Ironic Python Agent versions 10.2.0 prior to 10.2.3, 11.0.0 prior to 11.2.1, and 11.3.0 prior to 11.5.1. This vulnerability allows a malicious container, when deployed through the bootc deployment interface, to extract credentials used for downloading the container from the OCI registry. The issue arises because the Ironic Python Agent writes the pull secret to a file that is accessible to the container via the host's PID namespace.
Operators can apply the available patches for this vulnerability or disable the bootc deployment interface on their Ironic conductors.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2026 | CVE Modified | CVE |
| Jul 24, 2026 | New CVE Received | [email protected] |