CVE-2026-8058 Details
Description
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resource dump request stores that password into the BMC audit log where an admin user can see it.
A vulnerability exists in IBM OPENBMC firmware versions FW1110.00 through FW1110.20 and FW1060.00 through FW1060.71. The issue allows a user to include a password with a resource dump request, which is then recorded in the BMC audit log. This logged password can be viewed by an admin user, leading to an unauthorized exposure of sensitive information.
Users should upgrade to OPENBMC FW1110.30(1110_145) or newer. For those on the FW1060 branch, version 1060.72(1060_177), 1060.80(1060_185) or newer should be installed. The images can be downloaded from IBM Fix Central.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7280642 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm power system s1122 (9824-22a) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system s1122 (9824-22a) | All versions |
CPE
Remediation
| |
| ibm power system s1124 (9824-42a) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system s1124 (9824-42a) | All versions |
CPE
Remediation
| |
| ibm power system s1122s (9824-22b) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system s1122s (9824-22b) | All versions |
CPE
Remediation
| |
| ibm power system s1114 (9824-41b) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system s1114 (9824-41b) | All versions |
CPE
Remediation
| |
| ibm power system l1122 (9856-22h) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system l1122 (9856-22h) | All versions |
CPE
Remediation
| |
| ibm power system l1124 (9856-42h) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system l1124 (9856-42h) | All versions |
CPE
Remediation
| |
| ibm power system e1150 (9043-mru) firmware | >= fw1110.00, < fw1110.30 |
CPE
Remediation
| |
| ibm power system e1150 (9043-mru) | All versions |
CPE
Remediation
| |
| ibm power system s1022 (9105-22a) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system s1022 (9105-22a) | All versions |
CPE
Remediation
| |
| ibm power system s1024 (9105-42a) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system s1024 (9105-42a) | All versions |
CPE
Remediation
| |
| ibm power system s1022s (9105-22b) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system s1022s (9105-22b) | All versions |
CPE
Remediation
| |
| ibm power system s1014 (9105-41b) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system s1014 (9105-41b) | All versions |
CPE
Remediation
| |
| ibm power system l1022 (9786-22h) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system l1022 (9786-22h) | All versions |
CPE
Remediation
| |
| ibm power system l1024 (9786-42h) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system l1024 (9786-42h) | All versions |
CPE
Remediation
| |
| ibm power system e1050 (9043-mrx) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system e1050 (9043-mrx) | All versions |
CPE
Remediation
| |
| ibm power system s1012 (9028-21b) firmware | >= fw1060.00, < fw1060.72 |
CPE
Remediation
| |
| ibm power system s1012 (9028-21b) | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 26, 2026 | Initial Analysis | [email protected] |
| Jul 28, 2026 | CVE Modified | CISA-ADP |
| Jul 28, 2026 | New CVE Received | [email protected] |