Database/Firmware, BMC & network fabric

Eaton Tripp Lite series PADM firmware, session management interface: A low-privilege authenticated user escalates
Impact
A low-privilege authenticated user escalates to unrestricted device access. In practice that means a read-only monitoring account - the kind operators hand to a DCIM tool or an NOC vendor - becomes full control of rack power.
Who can reach it
Any authenticated user on the PDU, including the shared read-only accounts typically configured for monitoring integrations.
What to do
PADM firmware update or replacement for EOL SKUs. Separately, audit which third parties hold PDU accounts - monitoring integrations are the usual source of the low-privilege credential this bug needs.
References
Related entries
- Eaton Tripp Lite series PADM firmware, session management interface: An authenticated administrator can break outCVE-2026-22621 · Eaton Tripp Lite series PADM firmware, session management interfaceHigh
- NVIDIA UFM Enterprise: web interface authorization flaw leads to code execution on the fabric managerCVE-2026-24170 · NVIDIA UFM Enterprise (web interface authorization)High
- Linux kernel (drivers/infiniband/core): The RDMA user-capability check identified the capability file only by deviceCVE-2026-53188 · Linux kernel (drivers/infiniband/core)High
- Dell OpenManage Enterprise: authenticated low-privilege OS command injection on the management applianceCVE-2026-54795 · Dell OpenManage Enterprise (OS command injection)High
- Linux kernel mlx5_core IPsec offload / eswitch mode interlock: The acquire-SA path unconditionally callsCVE-2026-64522 · Linux kernel mlx5_core IPsec offload / eswitch mode interlockHigh
- MikroTik RouterOS: pre-auth btest session leaks kernel buffer data and can restart the deviceCVE-2026-67277 · MikroTik RouterOS (btest bandwidth test service)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.