Description
OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation without re-authentication.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The flaw in OpenBMC’s IPMI stack, phosphor-net-ipmid, lets an attacker replace the authorized account in an existing session with a different target account while preserving the session’s integrity and encryption. Because the new context is accepted without re‑authentication, an attacker can elevate privileges on a device that already has an IPMI session established. This is a classic bypass of authorization control (CWE‑863). The attacker gains the rights of the selected target account, potentially leading to full system compromise if that account has administrative privileges.

Affected Systems

The affected component is OpenBMC’s phosphor-net-ipmid module. Vendors that ship this module in their systems, such as NVIDIA and H3C, are potentially impacted. No specific version ranges are listed in the advisory; the issue applies to any deployment that uses the current implementation of phosphor-net-ipmid until a fixed release is available.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, but the EPSS score of less than 1% suggests that the vulnerability is not widely exploited in the wild yet. Because the vulnerability requires a pre‑existing IPMI session, it is likely exploited only by adversaries who can gain an initial session or who have compromised a system with open IPMI access. The omission from CISA’s KEV catalog confirms it has not been publicly exploited. Nonetheless, the potential for privilege escalation makes it a priority to patch or mitigate.

Generated by OpenCVE AI on September 17, 2026 at 15:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade phosphor-net-ipmid to a patched or newer version provided by the vendor as soon as it becomes available.
  • Restrict IPMI access to trusted management hosts and enforce the principle of least privilege, disabling unnecessary accounts that can be targeted.
  • Enable detailed logging of IPMI session creation and monitor for unexpected re‑targeting or privilege changes, and investigate any anomalies promptly.

Generated by OpenCVE AI on September 17, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Openbmc
Openbmc phosphor-net-ipmid
Vendors & Products Openbmc
Openbmc phosphor-net-ipmid

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
References

Tue, 15 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation without re-authentication.
Title OpenBMC IPMI Privilege Escalation via Retargeted RAKP 1
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Openbmc Phosphor-net-ipmid
cve-icon MITRE

Status: PUBLISHED

Assigner: runZero

Published:

Updated: 2026-09-15T15:00:15.848Z

Reserved: 2026-07-17T17:17:23.941Z

Link: CVE-2026-16140

cve-icon Vulnrichment

Updated: 2026-09-15T15:00:12.907Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T14:16:50.290

Modified: 2026-09-18T19:30:42.730

Link: CVE-2026-16140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:59:09Z

Weaknesses