Executive brief
IBM OpenBMC firmware, used to manage Power Systems hardware, contains a security flaw that allows users with restricted 'ReadOnly' access to increase their own permissions. An attacker with low-level credentials could exploit this to gain full administrator control over the Baseboard Management Controller (BMC). This could allow them to modify system settings or disrupt server operations.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the IBM OpenBMC HTTPS interface. The flaw allows an authenticated user with 'ReadOnly' privileges to bypass intended access controls and grant themselves 'Administrator' privileges. The vulnerability affects firmware versions FW1110.00 through FW1110.20 and FW1060.00 through FW1060.71 on IBM Power 10 and Power 11 systems. Attackers can exploit this over the network without user interaction, provided they have valid low-privileged credentials. IBM has released firmware updates FW1110.30 and FW1060.72/FW1060.80 to remediate the issue.
Affected products
- IBM OpenBMC FW1110 FW1110.00 through FW1110.20
- IBM OpenBMC FW1060 FW1060.00 through FW1060.71
Timeline
- 2026-07-21: disclosed: Initial publication by IBM
- 2026-07-28: advisory: NVD publication date