IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.

Project Subscriptions

Vendors Products
Openbmc Subscribe
Power System E1050 \(9043-mrx\) Subscribe
Power System E1050 \(9043-mrx\) Firmware Subscribe
Power System L1022 \(9786-22h\) Subscribe
Power System L1022 \(9786-22h\) Firmware Subscribe
Power System L1024 \(9786-42h\) Subscribe
Power System L1024 \(9786-42h\) Firmware Subscribe
Power System S1012 \(9028-21b\) Subscribe
Power System S1012 \(9028-21b\) Firmware Subscribe
Power System S1014 \(9105-41b\) Subscribe
Power System S1014 \(9105-41b\) Firmware Subscribe
Power System S1022 \(9105-22a\) Subscribe
Power System S1022 \(9105-22a\) Firmware Subscribe
Power System S1022s \(9105-22b\) Subscribe
Power System S1022s \(9105-22b\) Firmware Subscribe
Power System S1024 \(9105-42a\) Subscribe
Power System S1024 \(9105-42a\) Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

Customers with the products below should install FW1060.81(1060_191) or newer to remediate this vulnerability. Power 10 1) IBM Power System S1022 (9105-22A) 2) IBM Power System S1024 (9105-42A) 3) IBM Power System S1022s (9105-22B) 4) IBM Power System S1014 (9105-41B) 5) IBM Power System L1022 (9786-22H) 6) IBM Power System L1024 (9786-42H) 7) IBM Power System E1050 (9043-MRX) 8) IBM Power System S1012 (9028-21B) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/


Workaround

Protect access to the BMC's administrative interface.  Install firmware images only from trusted sources.  Validate the firmware image's integrity as described in the firmware "Release Notes" section "Firmware Information and Description" before installing it.

History

Wed, 02 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm power System E1050 \(9043-mrx\)
Ibm power System E1050 \(9043-mrx\) Firmware
Ibm power System L1022 \(9786-22h\)
Ibm power System L1022 \(9786-22h\) Firmware
Ibm power System L1024 \(9786-42h\)
Ibm power System L1024 \(9786-42h\) Firmware
Ibm power System S1012 \(9028-21b\)
Ibm power System S1012 \(9028-21b\) Firmware
Ibm power System S1014 \(9105-41b\)
Ibm power System S1014 \(9105-41b\) Firmware
Ibm power System S1022 \(9105-22a\)
Ibm power System S1022 \(9105-22a\) Firmware
Ibm power System S1022s \(9105-22b\)
Ibm power System S1022s \(9105-22b\) Firmware
Ibm power System S1024 \(9105-42a\)
Ibm power System S1024 \(9105-42a\) Firmware
CPEs cpe:2.3:h:ibm:power_system_e1050_\(9043-mrx\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1022_\(9786-22h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1024_\(9786-42h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1012_\(9028-21b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1014_\(9105-41b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1022_\(9105-22a\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1022s_\(9105-22b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1024_\(9105-42a\):-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:openbmc:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1050_\(9043-mrx\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1022_\(9786-22h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1024_\(9786-42h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1012_\(9028-21b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1014_\(9105-41b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1022_\(9105-22a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1022s_\(9105-22b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1024_\(9105-42a\)_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ibm power System E1050 \(9043-mrx\)
Ibm power System E1050 \(9043-mrx\) Firmware
Ibm power System L1022 \(9786-22h\)
Ibm power System L1022 \(9786-22h\) Firmware
Ibm power System L1024 \(9786-42h\)
Ibm power System L1024 \(9786-42h\) Firmware
Ibm power System S1012 \(9028-21b\)
Ibm power System S1012 \(9028-21b\) Firmware
Ibm power System S1014 \(9105-41b\)
Ibm power System S1014 \(9105-41b\) Firmware
Ibm power System S1022 \(9105-22a\)
Ibm power System S1022 \(9105-22a\) Firmware
Ibm power System S1022s \(9105-22b\)
Ibm power System S1022s \(9105-22b\) Firmware
Ibm power System S1024 \(9105-42a\)
Ibm power System S1024 \(9105-42a\) Firmware

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.
Title IBM OpenBMC Code Execution
First Time appeared Ibm
Ibm openbmc
Weaknesses CWE-22
CPEs cpe:2.3:o:ibm:openbmc:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:openbmc:fw1060.80:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm openbmc
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-21T16:13:25.891Z

Reserved: 2026-08-04T15:35:55.877Z

Link: CVE-2026-18849

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T21:16:54.663

Modified: 2026-09-02T18:58:30.013

Link: CVE-2026-18849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:30:16Z

Weaknesses