CVE-2026-8058
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
28/07/2026
Last modified:
26/08/2026
Description
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resource dump request stores that password into the BMC audit log where an admin user can see it.
Impact
Base Score 3.x
4.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:ibm:power_system_s1122_\(9824-22a\)_firmware:*:*:*:*:*:*:*:* | fw1110.00 (including) | fw1110.30 (excluding) |
| cpe:2.3:h:ibm:power_system_s1122_\(9824-22a\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ibm:power_system_s1124_\(9824-42a\)_firmware:*:*:*:*:*:*:*:* | fw1110.00 (including) | fw1110.30 (excluding) |
| cpe:2.3:h:ibm:power_system_s1124_\(9824-42a\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ibm:power_system_s1122s_\(9824-22b\)_firmware:*:*:*:*:*:*:*:* | fw1110.00 (including) | fw1110.30 (excluding) |
| cpe:2.3:h:ibm:power_system_s1122s_\(9824-22b\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ibm:power_system_s1114_\(9824-41b\)_firmware:*:*:*:*:*:*:*:* | fw1110.00 (including) | fw1110.30 (excluding) |
| cpe:2.3:h:ibm:power_system_s1114_\(9824-41b\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ibm:power_system_l1122_\(9856-22h\)_firmware:*:*:*:*:*:*:*:* | fw1110.00 (including) | fw1110.30 (excluding) |
| cpe:2.3:h:ibm:power_system_l1122_\(9856-22h\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ibm:power_system_l1124_\(9856-42h\)_firmware:*:*:*:*:*:*:*:* | fw1110.00 (including) | fw1110.30 (excluding) |
| cpe:2.3:h:ibm:power_system_l1124_\(9856-42h\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ibm:power_system_e1150_\(9043-mru\)_firmware:*:*:*:*:*:*:*:* | fw1110.00 (including) | fw1110.30 (excluding) |
| cpe:2.3:h:ibm:power_system_e1150_\(9043-mru\):-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ibm:power_system_s1022_\(9105-22a\)_firmware:*:*:*:*:*:*:*:* | fw1060.00 (including) | fw1060.72 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



