CVE-2026-18849
6.8
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Summary
IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | OPENBMC | FW1060.00 <= FW1060.80 | affected |
Weaknesses
- CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Workarounds
Protect access to the BMC's administrative interface. Install firmware images only from trusted sources. Validate the firmware image's integrity as described in the firmware "Release Notes" section "Firmware Information and Description" before installing it.
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.