Arbitrary Code Exec via grub-install in OpenStack iPythonAgent <11.5.0
CVE-2026-43003 Published on May 1, 2026

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.

NVD

Vulnerability Analysis

CVE-2026-43003 can be exploited with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Types

Inclusion of Functionality from Untrusted Control Sphere

The software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

What is a Shell injection Vulnerability?

The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

CVE-2026-43003 has been classified to as a Shell injection vulnerability or weakness.


Products Associated with CVE-2026-43003

stack.watch emails you whenever new vulnerabilities are published in OpenStack Ironic or Red Hat Openshift. Just hit a watch button to start following.

 
 

Affected Versions

OpenStack ironic-python-agent: Red Hat OpenShift Container Platform 4: Red Hat OpenShift Container Platform 4:

Exploit Probability

EPSS
0.81%
Percentile
53.01%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.