
OpenStack Ironic OSSA-2026-025: RBAC Bypass in IPMI Raw Command Execution (CVE-2026-54423) https://www.openwall.com/lists/oss-security/2026/07/08/3 OSSA-2026-026: Insufficient Access Controls regarding parent/child nodes (CVE-2026-44918) https://www.openwall.com/lists/oss-security/2026/07/08/4
Post summary
OpenStack Ironic advisories OSAA‑2026‑025 and OSAA‑2026‑026 disclose RBAC bypass in IPMI raw command execution and insufficient access controls for parent/child nodes, but provide no PoC, exploitation evidence, or patch details.
