Skip to content
CodeAuditAgent

CVE-2026-18849

IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.

Weakness

IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.

Affected products

  • ibm openbmc
  • ibm power_system_e1050_\(9043-mrx\)_firmware
  • ibm power_system_e1050_\(9043-mrx\)
  • ibm power_system_l1022_\(9786-22h\)_firmware
  • ibm power_system_l1022_\(9786-22h\)
  • ibm power_system_l1024_\(9786-42h\)_firmware
  • ibm power_system_l1024_\(9786-42h\)
  • ibm power_system_s1012_\(9028-21b\)_firmware

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.