Description
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrator privileges.
Published: 2026-07-28
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM OpenBMC firmware versions FW1110.00 through FW1110.20 and FW1060.00 through FW1060.71 allow a user with read‑only credentials to gain administrator privileges. The vulnerability is an instance of incorrect authorization (CWE‑863) and would give an attacker full control over the BMC interface, enabling modification of system configuration, firmware updates, or user accounts and thereby threatening confidentiality, integrity, and availability.

Affected Systems

IBM Power System models impacted include the Power 11 series: S1122, S1124, S1122s, S1114, L1122, L1124, and E1150; the recommended fix is firmware FW1110.30(1110_145) or newer. The Power 10 series affected models are S1022, S1024, S1022s, S1014, L1022, L1024, E1050, and S1012; the fix is firmware FW1060.72(1060_177), FW1060.80(1060_185) or newer. Any OpenBMC firmware before these revisions is vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker who has read‑only credentials, possibly through social engineering or compromise of existing accounts, could elevate to administrator level. The likely attack vector is through interfaces such as the BMC web UI or SSH, an inference based on the nature of the described privilege escalation.

Generated by OpenCVE AI on August 3, 2026 at 14:50 UTC.

Remediation

Vendor Solution

Customers with the products below should install FW1110.30(1110_145) or newer to remediate this vulnerability. Power 11 1) IBM Power System S1122 (9824-22A) 2) IBM Power System S1124 (9824-42A) 3) IBM Power System S1122s (9824-22B) 4) IBM Power System S1114 (9824-41B) 5) IBM Power System L1122 (9856-22H) 6) IBM Power System L1124 (9856-42H) 7) IBM Power System E1150 (9043-MRU) Customers with the products below should install FW1060.72(1060_177), FW1060.80(1060_185) or newer to remediate this vulnerability. Power 10 1) IBM Power System S1022 (9105-22A) 2) IBM Power System S1024 (9105-42A) 3) IBM Power System S1022s (9105-22B) 4) IBM Power System S1014 (9105-41B) 5) IBM Power System L1022 (9786-22H) 6) IBM Power System L1024 (9786-42H) 7) IBM Power System E1050 (9043-MRX) 8) IBM Power System S1012 (9028-21B) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/


Vendor Workaround

After applying this fix, ensure local BMC user accounts are as intended.  You can use the BMC's ASMI web application > Security and access > User management to view BMC accounts.


OpenCVE Recommended Actions

  • Update the OpenBMC firmware to FW1110.30(1110_145) or newer on all Power 11 models, or to FW1060.72(1060_177), FW1060.80(1060_185) or newer on all Power 10 models using the downloads from IBM Fix Central.
  • After applying the patch, review the BMC user accounts with the ASMI web application under Security and access > User management and remove any accounts that are no longer required, ensuring only authorized users retain administrative rights.
  • Monitor BMC access logs for unauthorized or suspicious activity and apply the latest firmware updates promptly as they become available.

Generated by OpenCVE AI on August 3, 2026 at 14:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrator privileges.
Title This Power System update is being released to address incorrect authorization
First Time appeared Ibm
Ibm openbmc
Weaknesses CWE-863
CPEs cpe:2.3:a:ibm:openbmc:fw1060.00.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1060.71.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1060.71:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.00.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.20.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.20:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm openbmc
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-28T17:36:01.738Z

Reserved: 2026-05-05T14:00:11.372Z

Link: CVE-2026-7868

cve-icon Vulnrichment

Updated: 2026-07-28T17:35:56.878Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-28T16:20:21.813

Modified: 2026-07-28T18:17:24.130

Link: CVE-2026-7868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:00:15Z

Weaknesses