Junglewise Threat Intelligence

CVE-2026-16140: OpenBMC phosphor-net-ipmid privilege escalation in RAKP authentication

CVE-2026-16140 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

OpenBMC's IPMI implementation (phosphor-net-ipmid) is a network management interface used in servers and data center equipment to enable remote administration and monitoring. A logic flaw allows an attacker with an existing authenticated session to escalate privileges to any target account without re-authentication, bypassing normal access controls and potentially gaining administrative control of affected servers.

Technical details

The vulnerability is a logic flaw in the RAKP (Remote Authentication Key Protocol) authentication mechanism within phosphor-net-ipmid. An attacker with an existing valid session can retarget the authorization context to a privileged account while maintaining the original session's integrity and encryption keys, effectively bypassing the re-authentication step required for privilege escalation. The attack requires an initial authenticated IPMI session but does not require network reachability to the targeted privileged account. The flaw allows privilege escalation without administrative credentials or password reset, granting the attacker full access to server management functions. Patches are expected from OpenBMC and downstream vendors including NVIDIA and H3C.

Affected products

  • OpenBMC phosphor-net-ipmid multiple versions
  • NVIDIA IPMI stack
  • H3C IPMI stack

Timeline

  • 2026-09-15: disclosed: CVE-2026-16140 publicly disclosed
  • 2026-09-15: advisory: runZero advisory published

References

Related threats