{"id":"CVE-2026-16140","title":"OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption k…","summary":"OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption k…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-863"],"vendor":"OpenBMC","product":"phosphor-net-ipmid","affected":["phosphor-net-ipmid <= ba6efc502e6b1fabb8ed1ca677ae5eedd64b6361"],"published":"2026-09-15","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:30:42.730","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-16140","references":[{"url":"https://www.runzero.com/advisories/openbmc-ipmi-privsec-rakp-cve-2026-16140/","label":"44488dab-36db-4358-99f9-bc116477f914"},{"url":"https://www.runzero.com/blog/lights-out-exposed/","label":"44488dab-36db-4358-99f9-bc116477f914"}],"tags":["nvd","cve.org"],"epss":0.00272,"epssPercentile":0.19777,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-15T15:00:05.940086Z"},"ingestedAt":"2026-09-15T14:38:16.196Z","slug":"CVE-2026-16140","body":"## Overview\n\nOpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation without re-authentication.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}