CVE-2026-66138: Ironic-Python-Agent pre-11.6.0 ntp_server shell exec
CVE-2026-66138 Published on July 24, 2026
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.
Vulnerability Analysis
CVE-2026-66138 is exploitable with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is a Shell injection Vulnerability?
The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVE-2026-66138 has been classified to as a Shell injection vulnerability or weakness.
Products Associated with CVE-2026-66138
Want to know whenever a new CVE is published for OpenStack Ironic Python Agent? stack.watch will email you.
Affected Versions
OpenStack Ironic Python Agent:- Version 11.6.0 is affected.
- Version 11.3.0, <= 11.5.1 is affected.
- Version 11.0.0, <= 11.2.1 is affected.
- Version 6.0.0, <= 10.2.3 is affected.