SEPTEMBER 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16140

HIGH · CVSS 8.8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

The vulnerability in OpenBMC's IPMI implementation allows an attacker to replace the authorization context of an existing session with that of a target account, enabling privilege escalation without requiring re-authentication. This flaw affects several downstream vendors, including NVIDIA and H3C, making it critical for organizations using their IPMI stacks to prioritize remediation efforts to prevent unauthorized access and potential exploitation.

CVE
CVE-2026-16140
Severity
HIGH
CVSS
8.8
EPSS
0.27%

Original NVD Description

OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation without re-authentication.