Junglewise Threat Intelligence

CVE-2026-71568: OpenShift Metal3 bmctest Ironic unauthenticated access

CVE-2026-71568 · Severity: medium · CVSS 5.3 · Published 2026-09-17

Executive brief

BMCtest is a testing tool for bare-metal provisioning that starts the Ironic API (which manages hardware provisioning) without authentication or encryption. During testing, anyone on the same network can access the Ironic API and potentially provision arbitrary images or modify firmware on enrolled machines. However, the attack window is narrow because it requires racing against the test itself, making exploitation difficult in practice.

Technical details

The vulnerability is a missing authentication issue (CWE-306) where Ironic is started without authentication and TLS during bmctest execution. The service listens on a non-loopback network interface, making it accessible to any network-connected attacker without privileges or user interaction required. An attacker could invoke Ironic API endpoints to provision arbitrary images or modify machine firmware, but must win a race condition with bmctest itself to do so before the test completes, significantly reducing the practical attack window. Patches are available in commits abcef65 and c6e5d04.

Affected products

  • OpenShift Metal3 bmctest <= 9ddd432

Timeline

  • 2026-08-18: disclosed
  • 2026-09-17: advisory: CVE-2026-71568 published
  • patched: Commits abcef65 and c6e5d04

References