Junglewise Threat Intelligence

CVE-2026-3821: Supermicro BMC command injection in SMASH services

CVE-2026-3821 · Severity: high · CVSS 8.8 · Published 2026-07-22

Executive brief

Supermicro server motherboards use a Baseboard Management Controller (BMC) to allow administrators to manage hardware remotely. A vulnerability in the SMASH management service could allow an authorized user to execute unauthorized commands on this controller. This could lead to a total loss of system control, data integrity issues, or a permanent shutdown of the server (Denial of Service).

Technical details

An OS command injection vulnerability (CWE-78) exists in the SMASH (Systems Management Architecture for Server Hardware) services of Supermicro BMC firmware. The flaw stems from improper neutralization of special elements within the SMASH input capability. An authenticated attacker with low privileges can exploit this over the network to execute arbitrary code with the privileges of the BMC service, potentially compromising the entire management subsystem or triggering a Denial-of-Service (DoS) state. The vulnerability affects multiple motherboard families including X12, X13, X14, and H12/H13/H14 series. Remediation requires updating the BMC firmware to the fixed versions specified in the Supermicro security advisory.

Affected products

  • Supermicro X14DBG-DAP BMC Firmware 01.00.16.00, 1.03.02.06
  • Supermicro X14DBI BMC Firmware 01.00.16.00, 1.03.02.06
  • Supermicro BMC Firmware (various motherboards) See advisory for full list of affected motherboard SKUs

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory
  • 2026-07-22: patched: Fixed firmware versions released for various motherboard models

References