GPU VulnDB

Database/Firmware, BMC & network fabric

IBM OpenBMC: ReadOnly BMC account can grant itself administrator privileges

CVE-2026-7868Firmware, BMC & network fabriccurated

Impact

A BMC account holding only the ReadOnly role can escalate itself to administrator. BMC administrator is out-of-band control of the machine: power cycling, virtual media and boot device selection, console access, sensor and firmware management - all of it below the host operating system and invisible to host-level controls. On a Power server carrying accelerators, that is the ability to take a node down or boot it from attacker-chosen media regardless of what the host or the scheduler thinks. ReadOnly BMC credentials are commonly handed to monitoring systems and shared with more people than admin credentials are, which is what makes the escalation meaningful.

Who can reach it

Anyone who can reach the BMC management interface and authenticate with a low-privilege ReadOnly account - normally the management VLAN, not the tenant network. Authentication is required, but only at the lowest role.

What to do

Update service processor firmware past the affected levels: FW1110.00 through FW1110.20 and FW1060.00 through FW1060.71 are affected; see IBM support node 7280641 for the fixed level for your machine type. This is a BMC firmware flash - plan it per node with the host out of service, since the service processor reboots. Until flashed, confirm the BMC network is reachable only from the management VLAN and audit which monitoring and vendor accounts hold ReadOnly.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.