---
id: CVE-2026-71568
title: "In BMCtest, Ironic is started without authentication and TLS for the duration of the test.\_Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity."
summary: "In BMCtest, Ironic is started without authentication and TLS for the duration of the test.\_Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity."
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-306
vendor: openshift-metal3
product: bmctest
affected:
  - bmctest <= 9ddd432
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:06:08.407'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71568'
references:
  - url: >-
      https://github.com/openshift-metal3/bmctest/security/advisories/GHSA-53vv-qh77-2hqh
    label: 74b3a70d-cca6-4d34-9789-e83b222ae3be
tags:
  - nvd
  - cve.org
epss: 0.00233
epssPercentile: 0.12734
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T19:34:16.588105Z'
ingestedAt: '2026-09-17T14:19:30.976Z'
---

## Overview

In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
