{"api_version":"1","generated_at":"2026-10-01T06:31:28+00:00","cve":"CVE-2026-71568","urls":{"html":"https://cve.report/CVE-2026-71568","api":"https://cve.report/api/cve/CVE-2026-71568.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-71568","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-71568"},"summary":{"title":"BMCtest exposes Ironic without authentication and TLS during the test","description":"In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.","state":"PUBLISHED","assigner":"redhat-cnalr","published_at":"2026-09-17 14:17:21","updated_at":"2026-09-18 19:06:08"},"problem_types":["CWE-306","CWE-306 CWE-306 Missing authentication for critical function"],"metrics":[{"version":"3.1","source":"74b3a70d-cca6-4d34-9789-e83b222ae3be","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","data":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/openshift-metal3/bmctest/security/advisories/GHSA-53vv-qh77-2hqh","name":"https://github.com/openshift-metal3/bmctest/security/advisories/GHSA-53vv-qh77-2hqh","refsource":"74b3a70d-cca6-4d34-9789-e83b222ae3be","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-71568","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71568","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"openshift-metal3","product":"bmctest","version":"affected 9ddd432 git","platforms":[]},{"source":"CNA","vendor":"openshift-metal3","product":"bmctest","version":"unaffected 153aefb git","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"71568","cve":"CVE-2026-71568","epss":"0.001620000","percentile":"0.058670000","score_date":"2026-09-21","updated_at":"2026-09-22 00:03:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-71568","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-17T19:34:16.588105Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-17T19:34:27.498Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unknown","product":"bmctest","repo":"https://github.com/openshift-metal3/bmctest/","vendor":"openshift-metal3","versions":[{"lessThanOrEqual":"9ddd432","status":"affected","version":"0","versionType":"git"},{"status":"unaffected","version":"153aefb","versionType":"git"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"In BMCtest, Ironic is started without authentication and TLS for the duration of the test.&nbsp;Exploiting the problem requires winning the race with <code>bmctest</code> itself, which reduces the attack window and significantly increases its complexity."}],"value":"In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"CWE-306 Missing authentication for critical function","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-17T13:46:16.878Z","orgId":"74b3a70d-cca6-4d34-9789-e83b222ae3be","shortName":"redhat-cnalr"},"references":[{"tags":["vendor-advisory"],"url":"https://github.com/openshift-metal3/bmctest/security/advisories/GHSA-53vv-qh77-2hqh"}],"source":{"discovery":"UNKNOWN"},"title":"BMCtest exposes Ironic without authentication and TLS during the test","x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"74b3a70d-cca6-4d34-9789-e83b222ae3be","assignerShortName":"redhat-cnalr","cveId":"CVE-2026-71568","datePublished":"2026-09-17T13:46:16.878Z","dateReserved":"2026-08-07T12:08:03.283Z","dateUpdated":"2026-09-17T19:34:27.498Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 14:17:21","lastModifiedDate":"2026-09-18 19:06:08","problem_types":["CWE-306","CWE-306 CWE-306 Missing authentication for critical function"],"metrics":{"cvssMetricV31":[{"source":"74b3a70d-cca6-4d34-9789-e83b222ae3be","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-17T19:34:16.588105Z","id":"CVE-2026-71568","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"71568","Ordinal":"1","Title":"BMCtest exposes Ironic without authentication and TLS during the","CVE":"CVE-2026-71568","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"71568","Ordinal":"1","NoteData":"In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.","Type":"Description","Title":"BMCtest exposes Ironic without authentication and TLS during the"}]}}}