CVE-2026-18849 (GCVE-0-2026-18849)
Vulnerability from cvelistv5
Published
2026-08-19 20:21
Modified
2026-08-21 16:13
CWE
  • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Summary
IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.
References
Impacted products
Vendor Product Version
IBM OPENBMC Version: FW1060.00    FW1060.80
    cpe:2.3:o:ibm:openbmc:fw1060.00:*:*:*:*:*:*:*
    cpe:2.3:o:ibm:openbmc:fw1060.80:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-18849",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-21T16:09:43.502126Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-21T16:13:25.891Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:o:ibm:openbmc:fw1060.00:*:*:*:*:*:*:*",
            "cpe:2.3:o:ibm:openbmc:fw1060.80:*:*:*:*:*:*:*"
          ],
          "product": "OPENBMC",
          "vendor": "IBM",
          "versions": [
            {
              "lessThanOrEqual": "FW1060.80",
              "status": "affected",
              "version": "FW1060.00",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.\u003c/p\u003e"
            }
          ],
          "value": "IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-22",
              "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-19T20:21:55.706Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7283590"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers with the products below should install FW1060.81(1060_191) or newer to remediate this vulnerability.\u003c/p\u003e\u003cp\u003ePower 10\u003cbr/\u003e1) IBM Power System S1022 (9105-22A)\u003cbr/\u003e2) IBM Power System S1024 (9105-42A)\u003cbr/\u003e3) IBM Power System S1022s (9105-22B)\u003cbr/\u003e4) IBM Power System S1014 (9105-41B)\u003cbr/\u003e5) IBM Power System L1022 (9786-22H)\u003cbr/\u003e6) IBM Power System L1024 (9786-42H)\u003cbr/\u003e7) IBM Power System E1050 (9043-MRX)\u003cbr/\u003e8) IBM Power System S1012 (9028-21B)\u003c/p\u003e\u003cp\u003eThe images mentioned above can be located at IBM Fix Central : \u003ca href=\"https://www.ibm.com/support/fixcentral/\" rel=\"nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/\u003c/a\u003e\u003c/p\u003e"
            }
          ],
          "value": "Customers with the products below should install FW1060.81(1060_191) or newer to remediate this vulnerability.\n\n\n\nPower 10\n1) IBM Power System S1022 (9105-22A)\n2) IBM Power System S1024 (9105-42A)\n3) IBM Power System S1022s (9105-22B)\n4) IBM Power System S1014 (9105-41B)\n5) IBM Power System L1022 (9786-22H)\n6) IBM Power System L1024 (9786-42H)\n7) IBM Power System E1050 (9043-MRX)\n8) IBM Power System S1012 (9028-21B)\n\n\n\nThe images mentioned above can be located at IBM Fix Central :  https://www.ibm.com/support/fixcentral/"
        }
      ],
      "title": "IBM OpenBMC Code Execution",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eProtect access to the BMC\u0027s administrative interface.\u00a0 Install firmware images only from trusted sources.\u00a0 Validate the firmware image\u0027s integrity as described in the firmware \"Release Notes\" section \"Firmware Information and Description\" before installing it.\u003c/p\u003e"
            }
          ],
          "value": "Protect access to the BMC\u0027s administrative interface.\u00a0 Install firmware images only from trusted sources.\u00a0 Validate the firmware image\u0027s integrity as described in the firmware \"Release Notes\" section \"Firmware Information and Description\" before installing it."
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-18849",
    "datePublished": "2026-08-19T20:21:55.706Z",
    "dateReserved": "2026-08-04T15:35:55.877Z",
    "dateUpdated": "2026-08-21T16:13:25.891Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…