← All CVEs

CVE-2026-18849

MEDIUM 6.8

Published 2026-08-19 · Last modified 2026-08-21

IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.

NO EXPLOITATION SIGNALS

No known exploitation, public exploit, or elevated probability at this time. Track for changes.

Exploitation likelihood

0.2%chance of exploitation in 30 days · 15th percentile

○ In CISA KEV ○ Public exploit / PoC

Impact if exploited

6.8CVSS 3.1 · MEDIUM

  • ConfidentialityHigh
  • IntegrityHigh
  • AvailabilityHigh

What an attacker needs

  • Access: Must sit on the same / adjacent network
  • Privileges: Requires an admin / high-privilege account
  • User interaction: No user interaction needed
  • Complexity: No special conditions — reliably repeatable

✓ lowers the bar for an attacker · ⚠ raises it

Proof of concept & exploit code

Test against your own equipment

curl -s https://vulnpedia.com/cve/CVE-2026-18849/poc.jsonMachine-readable PoC index for this CVE (for automation).

Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-18849/poc.json

Affected

Vendors Ibm

Products Openbmc Power System E1050 \(9043 Mrx\) Firmware Power System E1050 \(9043 Mrx\) Power System L1022 \(9786 22h\) Firmware Power System L1022 \(9786 22h\) Power System L1024 \(9786 42h\) Firmware Power System L1024 \(9786 42h\) Power System S1012 \(9028 21b\) Firmware Power System S1012 \(9028 21b\) Power System S1014 \(9105 41b\) Firmware Power System S1014 \(9105 41b\) Power System S1022 \(9105 22a\) Firmware

Weakness (CWE)

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Known Affected Software Configurations

VendorProductVersion range
IbmOpenbmc≥ fw1060.00 and ≤ fw1060.80
IbmPower System E1050 \(9043 Mrx\) Firmware≥ fw1060.00 and < fw1060.81
IbmPower System L1022 \(9786 22h\) Firmware≥ fw1060.00 and < fw1060.81
IbmPower System L1024 \(9786 42h\) Firmware≥ fw1060.00 and < fw1060.81
IbmPower System S1012 \(9028 21b\) Firmware≥ fw1060.00 and < fw1060.81
IbmPower System S1014 \(9105 41b\) Firmware≥ fw1060.00 and < fw1060.81
IbmPower System S1022 \(9105 22a\) Firmware≥ fw1060.00 and < fw1060.81
IbmPower System S1022s \(9105 22b\) Firmware≥ fw1060.00 and < fw1060.81
IbmPower System S1024 \(9105 42a\) Firmware≥ fw1060.00 and < fw1060.81

All CVSS metrics

  • MEDIUM 6.8 v3.1 · CNA Primary
    CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • MEDIUM 6.8 v3.1 · NVD Secondary
    CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References

Patches & mitigations

Sources: NVD · CVE.org · EPSS