Description

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.

INFO

Published Date :

2026-05-01T00:00:00.000Z

Last Modified :

2026-05-01T14:13:33.387Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2026-43003 vulnerability.

Vendors Products
Openstack
  • Ironic-python-agent
  • Ironic Python Agent

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact