PatchSiren

OpenBMC CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OpenBMC CVE published 2026-09-15

CVE-2026-16141

OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw allowing unauthenticated clients to bypass authentication. This vulnerability affects several downstream vendors, including NVIDIA and H3C, who implement this IPMI stack. The flaw enables an unauthenticated client to force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. As a [truncated]

HIGH OpenBMC CVE published 2026-09-15

CVE-2026-16140

OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw that allows for the replacement of an existing session's authorization context with a target account, effectively bypassing re-authentication requirements. This vulnerability enables privilege escalation and impacts several downstream vendors, including NVIDIA and H3C. Defenders should assess exposure, prioritize remediation, verify [truncated]