BMCtest exposes Ironic without authentication and TLS during the test
Summary
| CVE | CVE-2026-71568 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat-cnalr |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 14:17:21 UTC |
| Updated | 2026-09-18 19:06:08 UTC |
| Description | In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from 74b3a70d-cca6-4d34-9789-e83b222ae3be
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS: 0.001620000 probability, percentile 0.058670000 (date 2026-09-21)
Problem Types: CWE-306 | CWE-306 CWE-306 Missing authentication for critical function
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 74b3a70d-cca6-4d34-9789-e83b222ae3be | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
| 3.1 | CNA | CVSS | 5.3 | MEDIUM | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
AdjacentAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Openshift-metal3 | Bmctest | affected 9ddd432 git | Not specified |
| CNA | Openshift-metal3 | Bmctest | unaffected 153aefb git | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/openshift-metal3/bmctest/security/advisories/GHSA-53vv-qh77-2hqh | 74b3a70d-cca6-4d34-9789-e83b222ae3be | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.