CVE-2026-43003Disclosure(openstack / ironic_python_agent)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch openstack ironic_python_agent systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ironic_python_agent

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-01); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
ironic_python_agent

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-05-01: 3Mentions · 2026-06-18: 2Patch / Workaround · 2026-06-18: 1Technical Details · 2026-05-01: 2Technical Details · 2026-06-18: 205-0106-18
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-013
Disclosure3
2026-06-182
Disclosure1Patch1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    OSSN-0100: OpenStack Ironic: Command Injection in Ironic Python Agent (CVE-2026-43003) https://www.openwall.com/lists/oss-security/2026/06/16/11 when deploying a partition image that lacks boot artifacts. A malicious partition image can include [...] arbitrary binaries [...] which IPA executes on the provisioning

    Post summary

    The post discloses a command injection flaw in OpenStack Ironic’s Python agent, noting that malicious partition images can host arbitrary binaries executed during provisioning, and links to a mailing list discussion.

    10010275
    4.6K followersView on X
  • Can Artuc@canartuc
    Patch

    OpenStack Ironic patched CVE-2026-43003: a malicious partition image could execute crafted binaries inside a chroot during bootloader install on BIOS-booted nodes. Bare-metal provisioning means the attack surface is the hardware. Do you vet every image before it touches Ironic?

    Post summary

    CVE‑2026‑43003 in OpenStack Ironic was patched; the vulnerability allowed malicious partition images to run binaries inside a chroot during BIOS‑boot bootloader installation, but no active exploitation or PoC is reported.

    0000036
    171 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-43003 Arbitrary Code Execution in OpenStack Ironic-Python-Agent 1.0.0 Through 11.5.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43003

    Post summary

    The post announces CVE‑2026‑43003, an arbitrary code execution vulnerability affecting OpenStack Ironic‑Python‑Agent versions 1.0.0‑11.5.0.

    0000052
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-43003 An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the d… https://www.cve.org/CVERecord?id=CVE-2026-43003 ----- Traducción: CVE-2026-43003 Se … http://infoflow.cloud`

    Post summary

    A new CVE (CVE‑2026‑43003) affecting OpenStack ironic‑python‑agent 1.0.0‑11.5.0 is disclosed, noting that the agent can execute grub‑install from within a chroot; no exploit, patch, or active exploitation information is provided.

    0000025
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43003 An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the d… https://www.cve.org/CVERecord?id=CVE-2026-43003

    Post summary

    The text announces a discovered vulnerability in OpenStack ironic‑python‑agent, detailing the affected versions and the specific execution flaw, but does not provide PoC, exploit, or patch information.

    00000158
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenstackironic_python_agent---

Explore more