Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wqpv-c3pp-3m58 | OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere |
Thu, 30 Apr 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 29 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Non‑Default ipmitool Execution in OpenStack Ironic Console Interface | OpenStack Ironic: ipmitool: OpenStack Ironic: Arbitrary Code Execution via Remote Hardware Management |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 28 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Non‑Default ipmitool Execution in OpenStack Ironic Console Interface |
Tue, 28 Apr 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenStack Ironic through 25.0.0 allows ipmitool execution in a non-default configuration that has a console interface. | OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. |
Tue, 28 Apr 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenStack Ironic through 25.0.0 allows ipmitool execution in a non-default configuration that has a console interface. | |
| First Time appeared |
Openstack
Openstack ironic |
|
| Weaknesses | CWE-829 | |
| CPEs | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack ironic |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-30T03:05:07.152Z
Reserved: 2026-04-28T04:53:10.221Z
Link: CVE-2026-42510
Updated: 2026-04-30T03:05:07.152Z
Status : Awaiting Analysis
Published: 2026-04-28T06:16:04.100
Modified: 2026-04-30T04:16:14.493
Link: CVE-2026-42510
OpenCVE Enrichment
Updated: 2026-04-29T17:15:16Z
Github GHSA