Database/Control plane, storage & DevOps
Supermicro SMASH service (X14DBG-DAP, X14DBI): An attacker with any authorised BMC login escalates through the SMASH
Impact
An attacker with any authorised BMC login escalates through the SMASH shell to arbitrary code execution against the BMC, or knocks the controller offline entirely. On the DBG/DBI platform boards this is a current-generation GPU node, so the payoff is out-of-band control of live accelerator hardware: power cycling to disrupt long training runs, virtual-media boot into an attacker image, and a firmware-resident implant that persists across the node being returned to the pool. The CLI management shell exposed over SSH on the BMC of Supermicro's newest GPU-platform boards.
Who can reach it
An authenticated low-privilege BMC account with SSH reachability to the controller. Read-only or operator-tier BMC accounts handed to monitoring systems, support staff or tenants are enough - the privilege bar is low, and SMASH-over-SSH is enabled by default on these boards.
What to do
Firmware flash from Supermicro's July 2026 BMC/IPMI advisory batch. There is a genuine config-only mitigation here that most operators should apply regardless of patch state: disable the SSH/SMASH service on the BMC entirely if your tooling uses Redfish or IPMI-over-LAN, which removes this and the whole SMASH overflow family from your attack surface at zero rollout cost. Otherwise restrict SSH to the BMC to a management-host allowlist and audit every non-admin BMC account you have handed out.
References
Related entries
- Ceph RGW: unauthenticated STS token encryption lets any token holder bit-flip themselves to RGW adminCVE-2026-39944 · Ceph RADOS Gateway (STS session token AES-128-CBC handler)High
- MinIO (S3 API, Snowball auto-extract): The Snowball auto-extract path skips signature verification entirely, so anCVE-2026-40344 · MinIO (S3 API, Snowball auto-extract)High
- MinIO (S3 API, unsigned-trailer uploads): The signature on a query-string-credential unsigned-trailer upload is notCVE-2026-41145 · MinIO (S3 API, unsigned-trailer uploads)High
- JFrog Artifactory: token scope not validated, allowing privilege escalation from any low-privileged tokenCVE-2026-42016 · JFrog Artifactory Self-Hosted (access token scope validation)High
- OpenCost: unauthenticated POST /serviceKey overwrites the GCP service-account key fileCVE-2026-44300 · OpenCost (POST /serviceKey endpoint in pkg/costmodel/router.go)High
- VMware Avi Load Balancer: remote code execution on the Avi Controller control planeCVE-2026-47867 · VMware Avi Load Balancer (Controller control plane)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.