Description
In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass in Ironic during test runs
Action: Assess Impact
AI Analysis

Impact

A race condition in BMCtest allows Ironic to run temporarily without authentication or TLS, creating an unauthenticated entry point into the service. The flaw does not provide direct remote code execution; instead, it enables an attacker who can time the race with bmctest to connect to Ironic and perform operations that the service normally protects, potentially leading to unauthorized data exposure or configuration changes. The vulnerability is an instance of missing authentication (CWE‑306) and is limited to the test harness environment, but the narrow attack window increases implementation difficulty. It does not affect normal production deployments of Ironic unless the test setup is mirrored in production.

Affected Systems

The issue affects the openshift-metal3:bmctest component. The affected product is the BMCtest test harness used to validate OpenShift Metal3 deployments. No specific version numbers are listed in the CNA data, so all current releases that use the default test harness configuration are presumed vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, but the requirement to race with BMCtest narrows the attack window and raises complexity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely need to exploit a timing window during test execution, which limits the practicality of large‑scale attacks but does raise concern for developers and testers. The threat is primarily to those who rely on the default BMCtest configuration and could inadvertently expose Ironic endpoints to network attackers during test cycles.

Generated by OpenCVE AI on September 17, 2026 at 22:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a BMCtest release that enables authentication and TLS for Ironic before tests begin
  • If an upgrade is unavailable, manually configure the Ironic service to require authentication and TLS while the test harness runs
  • Restrict network access to the Ironic endpoint so only trusted test hosts can reach it during the test period
  • Regularly review Ironic access logs for any unauthorized connections during testing

Generated by OpenCVE AI on September 17, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Openshift-metal3
Openshift-metal3 bmctest
Vendors & Products Openshift-metal3
Openshift-metal3 bmctest

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.
Title BMCtest exposes Ironic without authentication and TLS during the test
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Openshift-metal3 Bmctest
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat-cnalr

Published:

Updated: 2026-09-17T19:34:27.498Z

Reserved: 2026-08-07T12:08:03.283Z

Link: CVE-2026-71568

cve-icon Vulnrichment

Updated: 2026-09-17T19:34:22.933Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T14:17:21.013

Modified: 2026-09-18T19:06:08.407

Link: CVE-2026-71568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:15Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function