CVE-2026-18849
IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.
Published:Aug 19, 2026
Last Modified:Sep 2, 2026
EPS:Aug 19, 2026
EPSS Score:0.0024
CVSS Score:6.8
Affected Products
Vendor
Product
Action
Vendor
Ibm
Product
Openbmc
Ibm
Openbmc
Vendor
Ibm
Product
Power System E1050 \(9043-mrx\)
Ibm
Power System E1050 \(9043-mrx\)
Vendor
Ibm
Product
Power System E1050 \(9043-mrx\) Firmware
Ibm
Power System E1050 \(9043-mrx\) Firmware
Vendor
Ibm
Product
Power System L1022 \(9786-22h\)
Ibm
Power System L1022 \(9786-22h\)
Vendor
Ibm
Product
Power System L1022 \(9786-22h\) Firmware
Ibm
Power System L1022 \(9786-22h\) Firmware
Vendor
Ibm
Product
Power System L1024 \(9786-42h\)
Ibm
Power System L1024 \(9786-42h\)
Vendor
Ibm
Product
Power System L1024 \(9786-42h\) Firmware
Ibm
Power System L1024 \(9786-42h\) Firmware
Vendor
Ibm
Product
Power System S1012 \(9028-21b\)
Ibm
Power System S1012 \(9028-21b\)
Vendor
Ibm
Product
Power System S1012 \(9028-21b\) Firmware
Ibm
Power System S1012 \(9028-21b\) Firmware
Vendor
Ibm
Product
Power System S1014 \(9105-41b\)
Ibm
Power System S1014 \(9105-41b\)
Vendor
Ibm
Product
Power System S1014 \(9105-41b\) Firmware
Ibm
Power System S1014 \(9105-41b\) Firmware
Vendor
Ibm
Product
Power System S1022 \(9105-22a\)
Ibm
Power System S1022 \(9105-22a\)
Vendor
Ibm
Product
Power System S1022 \(9105-22a\) Firmware
Ibm
Power System S1022 \(9105-22a\) Firmware
Vendor
Ibm
Product
Power System S1022s \(9105-22b\)
Ibm
Power System S1022s \(9105-22b\)
Vendor
Ibm
Product
Power System S1022s \(9105-22b\) Firmware
Ibm
Power System S1022s \(9105-22b\) Firmware
Vendor
Ibm
Product
Power System S1024 \(9105-42a\)
Ibm
Power System S1024 \(9105-42a\)
Vendor
Ibm
Product
Power System S1024 \(9105-42a\) Firmware
Ibm
Power System S1024 \(9105-42a\) Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
