PatchSiren cyber security CVE debrief
CVE-2026-16140 OpenBMC CVE debrief
OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw that allows for the replacement of an existing session's authorization context with a target account, effectively bypassing re-authentication requirements. This vulnerability enables privilege escalation and impacts several downstream vendors, including NVIDIA and H3C. Defenders should assess exposure, prioritize remediation, verify affected versions, and apply vendor patches. The issue arises from a flaw in the IPMI implementation, which maintains the original integrity and encryption keys while allowing unauthorized access. To address this vulnerability, defenders must review affected product deployments,
- Vendor
- OpenBMC
- Product
- phosphor-net-ipmid
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for OpenBMC IPMI implementations, particularly those using downstream vendor solutions like NVIDIA and H3C, should assess exposure and prioritize remediation.
Why it matters
CVE-2026-16140 allows privilege escalation in OpenBMC's IPMI implementation without re-authentication, affecting downstream vendors. Defenders should assess exposure, prioritize remediation, and verify affected versions and patches.
- Privilege escalation without re-authentication
- Potential for unauthorized access and control
- Need for verification of affected versions and vendor patches
- Remediation priority for OpenBMC IPMI implementations
Technical summary
OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw that allows the authorization context of an existing session to be replaced with a target account while maintaining the original integrity and encryption keys. This issue effectively enables privilege escalation without re-authentication and affects several downstream vendors, including NVIDIA and H3C. The vulnerability arises from a flaw in the IPMI implementation's session management, which could allow unauthorized access to IPMI functions.
Defensive priority
High
Recommended defensive actions
- Assess exposure and prioritize remediation for OpenBMC IPMI implementations
- Verify affected versions and vendor patches
- Implement compensating controls and monitor for exploitation attempts
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but specific affected versions, remediation steps, and vendor patches require verification from official sources. The OpenBMC community and downstream vendors like NVIDIA and H3C have acknowledged the issue. However, the extent of affected systems and detailed mitigation strategies are not explicitly stated in the CVE record or NVD entry. Defenders should consult official advisories and verify the integrity of their IPMI implementations to ensure they are not exposed.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16140 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16140
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16140 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16140
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.runzero.com/advisories/openbmc-ipmi-privsec-rakp-cve-2026-16140/
44488dab-36db-4358-99f9-bc116477f914
-
Source reference
Unverified legacy reference
URL: https://www.runzero.com/blog/lights-out-exposed/
44488dab-36db-4358-99f9-bc116477f914
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.