Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 15 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation without re-authentication. | |
| Title | OpenBMC IPMI Privilege Escalation via Retargeted RAKP 1 | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: runZero
Published:
Updated: 2026-09-15T15:00:15.848Z
Reserved: 2026-07-17T17:17:23.941Z
Link: CVE-2026-16140
Updated: 2026-09-15T15:00:12.907Z
Status : Received
Published: 2026-09-15T14:16:50.290
Modified: 2026-09-15T15:17:13.270
Link: CVE-2026-16140
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization