CVE-2026-7868 Details
Description
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrator privileges.
A vulnerability in IBM OpenBMC versions FW1110.00 through FW1110.20 and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and gain administrator rights. This issue affects the BMC's HTTPS interface for ReadOnly user accounts.
Users should upgrade to OpenBMC FW1110.30(1110_145) or FW1060.72(1060_177), FW1060.80(1060_185) or newer. The images can be downloaded from IBM Fix Central.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7280641 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm power system s1122 (9824-22a) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system s1122 (9824-22a) | All versions |
CPE
Remediation
| |
| ibm power system s1124 (9824-42a) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system s1124 (9824-42a) | All versions |
CPE
Remediation
| |
| ibm power system s1122s (9824-22b) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system s1122s (9824-22b) | All versions |
CPE
Remediation
| |
| ibm power system s1114 (9824-41b) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system s1114 (9824-41b) | All versions |
CPE
Remediation
| |
| ibm power system l1122 (9856-22h) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system l1122 (9856-22h) | All versions |
CPE
Remediation
| |
| ibm power system l1124 (9856-42h) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system l1124 (9856-42h) | All versions |
CPE
Remediation
| |
| ibm power system e1150 (9043-mru) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system e1150 (9043-mru) | All versions |
CPE
Remediation
| |
| ibm power system s1022 (9105-22a) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system s1022 (9105-22a) | All versions |
CPE
Remediation
| |
| ibm power system s1024 (9105-42a) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system s1024 (9105-42a) | All versions |
CPE
Remediation
| |
| ibm power system s1022s (9105-22b) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system s1022s (9105-22b) | All versions |
CPE
Remediation
| |
| ibm power system s1014 (9105-41b) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system s1014 (9105-41b) | All versions |
CPE
Remediation
| |
| ibm power system l1022 (9786-22h) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system l1022 (9786-22h) | All versions |
CPE
Remediation
| |
| ibm power system l1024 (9786-42h) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system l1024 (9786-42h) | All versions |
CPE
Remediation
| |
| ibm power system e1050 (9043-mrx) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system e1050 (9043-mrx) | All versions |
CPE
Remediation
| |
| ibm power system s1012 (9028-21b) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system s1012 (9028-21b) | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 26, 2026 | Initial Analysis | [email protected] |
| Jul 28, 2026 | CVE Modified | CISA-ADP |
| Jul 28, 2026 | New CVE Received | [email protected] |