Junglewise Threat Intelligence

CVE-2026-8058: IBM OpenBMC sensitive information disclosure in audit logs

CVE-2026-8058 · Severity: medium · CVSS 4.5 · Published 2026-07-28

Technologies: IBM OPENBMC FW1110. Vendors: IBM.

Executive brief

IBM Power Systems using OpenBMC firmware are affected by a security flaw where user passwords may be recorded in plain text within system audit logs. This occurs when a user includes a password as part of a diagnostic 'resource dump' request. An administrative user with access to these logs could view these passwords, potentially leading to unauthorized access or further compromise of the system.

Technical details

A sensitive information disclosure vulnerability (CWE-200) exists in the diagnostic interface of IBM OpenBMC firmware. When a user initiates a resource dump request and includes a password, the firmware incorrectly logs the full request, including the password, into the BMC audit log. An attacker with administrative privileges (PR:H) could read these logs to recover user credentials. The vulnerability affects Power 10 and Power 11 systems. Remediation is available in firmware versions FW1110.30 (1110_145), 1060.72 (1060_177), and 1060.80 (1060_185) or newer.

Affected products

  • IBM OPENBMC FW1110 FW1110.00 through FW1110.20
  • IBM OPENBMC FW1060 FW1060.00 through FW1060.71

Timeline

  • 2026-07-21: disclosed: Initial publication by IBM
  • 2026-07-28: advisory: NVD publication date

References

Related threats