CVE-2026-71568 PUBLISHED

BMCtest exposes Ironic without authentication and TLS during the test

Assigner: redhat-cnalr
Reserved: 07.08.2026 Published: 17.09.2026 Updated: 17.09.2026

In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 5.3

Product Status

Vendor openshift-metal3
Product bmctest
Versions Default: unknown
  • affected from 0 to 9ddd432 (incl.)
  • Version 153aefb is unaffected

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE