CVE-2026-8058

Summary

IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resource dump request stores that password into the BMC audit log where an admin user can see it.

Affected Software

VendorProductVersion RangeStatus
IBMOPENBMCFW1110.00 <= FW1110.20affected
IBMOPENBMCFW1060.00 <= FW1060.71affected

Weaknesses

  • CWE-200: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Workarounds

Protect access to the BMC's administrative functions.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References