Password Exposure in IBM OPENBMC Firmware Versions
CVE-2026-8058

4.5MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-8058?

A vulnerability in IBM OPENBMC Firmware allows users to supply a password during a resource dump request. This password is inadvertently stored in the BMC audit log, making it accessible to administrative users. The improper handling of sensitive information poses a significant risk, granting unauthorized access to critical credentials, and highlights the importance of securing log files from exposure.

Affected Version(s)

OPENBMC FW1110.00

OPENBMC FW1060.00

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.