CVE-2026-18849

Summary

IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.

Affected Software

VendorProductVersion RangeStatus
IBMOPENBMCFW1060.00 <= FW1060.80affected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Workarounds

Protect access to the BMC's administrative interface.  Install firmware images only from trusted sources.  Validate the firmware image's integrity as described in the firmware "Release Notes" section "Firmware Information and Description" before installing it.

References