IBM Openbmc
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM Openbmc.
By the Year
In 2026 there have been 5 vulnerabilities in IBM Openbmc with an average score of 5.3 out of ten. Openbmc did not have any published security vulnerabilities last year. That is, 5 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 5 | 5.30 |
| 2025 | 0 | 0.00 |
| 2024 | 2 | 7.50 |
It may take a day or so for new Openbmc vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Openbmc Security Vulnerabilities
IBM OpenBMC BMC Fw mgmt Crash/Leak (FW1060-1120)
CVE-2026-18857
3.4 - Low
- September 24, 2026
IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interface. The host system can cause the BMC firmware management service to crash or allow a limited amount of BMC internal memory to be read, resulting in a confidentiality and availability impact to the managed system.
Out-of-bounds Read
Arbitrary Code Exec via BMC Firmware Update in IBM OpenBMC (FW1060)
CVE-2026-18849
6.8 - Medium
- August 19, 2026
IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.
Directory traversal
CVE-2026-7868 IBM FW1110.00-FW1110.20/1060.00-1060.71 R/O PrivEsc
CVE-2026-7868
6.5 - Medium
- July 28, 2026
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrator privileges.
AuthZ
IBM OpenBMC Password Leak in Audit Log (FW 1060/1110 Series)
CVE-2026-8058
4.5 - Medium
- July 28, 2026
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resource dump request stores that password into the BMC audit log where an admin user can see it.
Information Disclosure
IBM OPENBMC FW1110.001110.11 DoS via unauthenticated network
CVE-2026-7254
5.3 - Medium
- May 27, 2026
IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.
Improper Validation of Specified Quantity in Input
OpenBMC default pwd/session flaw: admin access (FW1020-60, FW1030-50, FW1050-10)
CVE-2024-35124
7.5 - High
- August 13, 2024
A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.
Missing Authentication for Critical Function
IBM OpenBMC FW1050.00FW1050.10 BMCWeb HTTPS Auth Bypass
CVE-2024-31916
7.5 - High
- June 27, 2024
IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses authentication channels. IBM X-ForceID: 290026.
Missing Authentication for Critical Function
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Openbmc or by IBM? Click the Watch button to subscribe.