Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Customers with the products below should install FW1060.81(1060_191) or newer to remediate this vulnerability. Power 10 1) IBM Power System S1022 (9105-22A) 2) IBM Power System S1024 (9105-42A) 3) IBM Power System S1022s (9105-22B) 4) IBM Power System S1014 (9105-41B) 5) IBM Power System L1022 (9786-22H) 6) IBM Power System L1024 (9786-42H) 7) IBM Power System E1050 (9043-MRX) 8) IBM Power System S1012 (9028-21B) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/
Vendor Workaround
Protect access to the BMC's administrative interface. Install firmware images only from trusted sources. Validate the firmware image's integrity as described in the firmware "Release Notes" section "Firmware Information and Description" before installing it.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7283590 |
|
Wed, 19 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact. | |
| Title | IBM OpenBMC Code Execution | |
| First Time appeared |
Ibm
Ibm openbmc |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:o:ibm:openbmc:fw1060.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:openbmc:fw1060.80:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm openbmc |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-08-19T20:21:55.706Z
Reserved: 2026-08-04T15:35:55.877Z
Link: CVE-2026-18849
No data.
No data.
No data.
OpenCVE Enrichment
No data.