What is CVE-2026-18849?
This CVE identifies a vulnerability in the BMC firmware update process of IBM OpenBMC versions FW1060.00 through FW1060.80. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, impacting confidentiality, integrity, and availability. It is strongly recommended to update the affected firmware to the latest version immediately.
Azərbaycanca: Bu CVE, IBM OpenBMC proqram təminatının FW1060.00 - FW1060.80 versiyalarında BMC firmware yeniləmə prosesində aşkarlanmış boşluqdur. BMC-yə autentifikasiya olunmuş administrator səviyyəsində girişi olan təcavüzkar müəyyən şərtlər altında ixtiyari kod icra edə bilər ki, bu da məxfilik, bütövlük və əlçatanlığa təsir göstərir. Təsirə məruz qalan sistemlərin dərhal ən son firmware versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: shared vendor: IBM
FAQ2
What level of access does an attacker need to exploit the CVE-2026-18849 vulnerability?
To exploit this vulnerability, an attacker requires authenticated administrator-level access to the BMC.
Which versions of IBM OpenBMC software are affected by the CVE-2026-18849 vulnerability?
The vulnerability affects IBM OpenBMC software versions FW1060.00 through FW1060.80.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.