---
id: CVE-2026-43003
title: An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0
summary: >-
  An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0.
  Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot
  of the deployed partition image, leading to code execution in the case of a
  mal…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-829
  - CWE-78
vendor: openstack
product: ironic_python_agent
affected:
  - 'ironic_python_agent >= 1.0.0, <= 11.5.0'
patched:
  - openshift_container_platform 4.19
  - openshift_container_platform 4.21
  - openshift_container_platform 4.22
  - openshift_container_platform 4.2
published: '2026-05-01'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T13:20:05.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-43003'
references:
  - url: 'https://bugs.launchpad.net/ironic-python-agent/+bug/2148310'
    label: cve@mitre.org
  - url: >-
      https://github.com/openstack/ironic-python-agent/blob/236b33abffe6688afc39c21e351cc3889b3db2dd/ironic_python_agent/efi_utils.py#L134-L139
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/06/16/11'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2026:51038'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:57801'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60446'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60454'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-43003'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2464306'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43003.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-43003'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-43003'
  - url: 'https://github.com/openstack/ironic-python-agent'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/ironic-python-agent/PYSEC-2026-205.yaml
  - url: >-
      https://opendev.org/openstack/ironic-python-agent/commit/6cd463a657edcddf7b79416ac69bdef5b6f30099
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - osv
  - pip
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-05-01T14:13:22.620791Z'
epss: 0.01126
epssPercentile: 0.64984
aliases:
  - GHSA-rmxr-45gj-889w
  - PYSEC-2026-205
ecosystem: pip
scores:
  nvd: 8
  cna: 8
  vendor: 8.5
ingestedAt: '2026-07-08T18:25:52.991Z'
---

## Overview

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.

## Affected

- `ironic_python_agent >= 1.0.0, <= 11.5.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-43003)

Affected packages:

- `ironic-python-agent >= 1.0.0, < 11.6.0`

Patched in:

- `ironic-python-agent 11.6.0`

Source: https://osv.dev/vulnerability/GHSA-rmxr-45gj-889w

## Vendor advisories

- **RHSA-2026:60454** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:60454)
- **RHSA-2026:57801** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.21 · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:57801)
- **RHSA-2026:51038** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.22 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:51038)
- **RHSA-2026:60446** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.2 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:60446)
- **Red Hat VEX** · Important · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43003.json)
