CVE-2026-18849

IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.
References
Link Resource
https://www.ibm.com/support/pages/node/7283590 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:o:ibm:openbmc:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ibm:power_system_e1050_\(9043-mrx\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e1050_\(9043-mrx\):-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ibm:power_system_l1022_\(9786-22h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1022_\(9786-22h\):-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ibm:power_system_l1024_\(9786-42h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1024_\(9786-42h\):-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ibm:power_system_s1012_\(9028-21b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1012_\(9028-21b\):-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ibm:power_system_s1014_\(9105-41b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1014_\(9105-41b\):-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ibm:power_system_s1022_\(9105-22a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1022_\(9105-22a\):-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ibm:power_system_s1022s_\(9105-22b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1022s_\(9105-22b\):-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:ibm:power_system_s1024_\(9105-42a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1024_\(9105-42a\):-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-19 21:16

Updated : 2026-09-02 18:58


NVD link : CVE-2026-18849

Mitre link : CVE-2026-18849

CVE.ORG link : CVE-2026-18849


JSON object : View

Products Affected

ibm

  • power_system_s1024_\(9105-42a\)
  • openbmc
  • power_system_e1050_\(9043-mrx\)_firmware
  • power_system_s1024_\(9105-42a\)_firmware
  • power_system_s1012_\(9028-21b\)
  • power_system_s1014_\(9105-41b\)
  • power_system_s1022_\(9105-22a\)_firmware
  • power_system_s1022s_\(9105-22b\)
  • power_system_s1012_\(9028-21b\)_firmware
  • power_system_s1022_\(9105-22a\)
  • power_system_l1024_\(9786-42h\)_firmware
  • power_system_l1022_\(9786-22h\)
  • power_system_s1014_\(9105-41b\)_firmware
  • power_system_s1022s_\(9105-22b\)_firmware
  • power_system_l1024_\(9786-42h\)
  • power_system_l1022_\(9786-22h\)_firmware
  • power_system_e1050_\(9043-mrx\)
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')