What is CVE-2026-8058?
This vulnerability is found in IBM OPENBMC firmware, where providing a password with a resource dump request causes that password to be stored in plain text within the BMC audit log, visible to admin users. Affected versions range from FW1110.00 through FW1110.20 and FW1060.00 through FW1060.71; organizations using these versions should immediately apply vendor-provided updates and restrict access to the audit log.
Azərbaycanca: Bu zəiflik IBM OPENBMC proqram təminatında aşkar edilib, burada istifadəçi resurs dump sorğusuna parol əlavə etdikdə həmin parol BMC audit jurnalında açıq mətn şəklində saxlanır və admin istifadəçisi tərəfindən görülə bilir. Təsirə məruz qalan versiyalar FW1110.00-dan FW1110.20-yə və FW1060.00-dan FW1060.71-ə qədərdir; bu versiyaları işlədən təşkilatlar dərhal istehsalçı tərəfindən təqdim edilən yeniləmələri tətbiq etməli və audit jurnalına girişi məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: IBM
FAQ2
How is CVE-2026-8058 exploited in IBM OPENBMC firmware?
When a user provides a password with a resource dump request, that password is stored in plain text within the BMC audit log, visible to admin users.
Which IBM OPENBMC versions are affected by CVE-2026-8058?
Versions ranging from FW1110.00 through FW1110.20 and FW1060.00 through FW1060.71 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.