CVE-2026-66138
CVE-2026-66138: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh8.8
High [CVE-2026-66138] Arbitrary code execution via malicious configuration
CVE-2026-66138Source published Source updated
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell. A vulnerability was found in Ironic-Python-Agent's (IPA) time syncing code. The value of the ntp_server configuration option is inserted into a shell command without sanitization. This command is run as root very early in the IPA startup flow, allowing an attacker to run arbitrary commands as root. This value can be set in three ways; directly in an operator-created ramdisk, set via kernel command line using Ironic, or passing the parameters via mDNS responder for mDNS enabled installation. For the most common, and highest…
- Affected products in this advisory
- Red Hat OpenShift Container Platform 4.20
- Red Hat OpenShift Container Platform 4.21
- Red Hat OpenShift Container Platform 4.22
- Red Hat OpenStack Platform 17.1
1 more entries in the full advisory.
- Source-reported affected versions
- 11.6.0
- Source-reported fixed versions
- openshift4/ose-ironic-agent-rhel9:1787735456
- openshift4/ose-ironic-agent-rhel9:1787555677
- openshift4/ose-ironic-agent-rhel9:1787073364
- RHSA-2026:60446
2 more entries in the full advisory.
- Mitigation guidance
- Remove the chronyd binary from the Ironic Python Agent (IPA) ramdisk image. The vulnerable code path is only reached when chronyd is detected as available. Without chronyd, IPA will either use ntpdate for time synchronization (which is not affected by this vulnerability, as it passes the NTP server address as a separate process argument without shell interpolation) or skip time synchronization entirely if neither tool is available. Additionally, restrict and segment the provisioning network to prevent rogue mDNS responders, and review OpenStack RBAC policies to limit which users can modify kernel_append_params on bare metal nodes.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.