CVE-2026-7868

Summary

IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrator privileges.

Affected Software

VendorProductVersion RangeStatus
IBMOPENBMCFW1110.00 <= FW1110.20affected
IBMOPENBMCFW1060.00 <= FW1060.71affected

Weaknesses

  • CWE-863: CWE-863 Incorrect Authorization

Workarounds

After applying this fix, ensure local BMC user accounts are as intended.  You can use the BMC's ASMI web application > Security and access > User management to view BMC accounts.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References