THREAT OPS › Threat News › [NVD] CVE-2026-43003 (HIGH 8.0) — An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.
[NVD] CVE-2026-43003 (HIGH 8.0) — An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.
CVE-2026-43003 CVSS: 8.0 HIGH Published: 2026-05-01T09:16:17.440
An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.
MITRE ATT&CK techniques
- Malicious ImageT1204.003
Indicators of compromise
- CVE-2026-43003cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-43003