Red HatCVE-2026-71568
Red Hat bmctest: missing authentication
Medium5.3CVE-2026-71568 · Published Sep 17, 2026 · updated Sep 18, 2026
In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| bmctest Product | <= 9ddd432 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-306
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 17 | Red Hat Keycloak.: capture-replay | High7.4 | 26.7.4 |
| Sep 17 | Red Hat libxml2: null pointer dereference | Medium5.5 | No fix yet |
| Sep 17 | Red Hat quarkus-websockets-next. This vulnerability: denial of service | High7.5 | No fix yet |
| Sep 17 | Red Hat SmallRye JWT: path traversal | Medium5.3 | No fix yet |
| Sep 17 | Red Hat Satellite 6: improper authorization | Medium4.3 | No fix yet |
| Sep 17 | Redis community: out-of-bounds read | High7.1 | No fix yet |