---
id: CVE-2026-54422
title: "In OpenStack\_Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials\_used to download it."
summary: "In OpenStack\_Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials\_used to download it."
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N'
cwe:
  - CWE-522
published: '2026-07-24'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:03:22.897'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54422'
references:
  - url: 'https://bugs.launchpad.net/ironic-python-agent/+bug/2155826'
    label: cve@mitre.org
  - url: 'https://security.openstack.org/ossa/OSSA-2026-028.html'
    label: cve@mitre.org
  - url: 'https://www.openwall.com/lists/oss-security/2026/07/23/4'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/07/23/4'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00122
epssPercentile: 0.023
ingestedAt: '2026-09-09T16:14:05.510Z'
---

## Overview

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
