<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Openbmc - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/openbmc/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 15:31:02 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/openbmc/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation Vulnerability in OpenBMC phosphor-net-ipmid (CVE-2026-16140)</title><link>https://feed.craftedsignal.io/briefs/2026-09-openbmc-privilege-escalation/</link><pubDate>Tue, 15 Sep 2026 15:31:02 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-openbmc-privilege-escalation/</guid><description>A logic flaw in OpenBMC's phosphor-net-ipmid implementation allows authenticated remote attackers to hijack existing sessions and perform unauthorized privilege escalation.</description><content:encoded><![CDATA[<p>OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a critical logic flaw (CVE-2026-16140) in its Remote Authentication and Key Exchange (RAKP) mechanism. An attacker who has already established a low-privilege session can trigger this vulnerability to replace their current authorization context with that of a target account, such as an administrator, without requiring re-authentication. The vulnerability persists because the session maintains the original integrity and encryption keys even after the authorization context is swapped. This flaw poses a significant risk to data center infrastructure, as OpenBMC is widely utilized in server management stacks by various vendors, including NVIDIA and H3C. Given the availability of public proof-of-concept exploit code, administrators should prioritize identifying and patching impacted BMC firmware.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-16140 allows an attacker to achieve full unauthorized control over the baseboard management controller (BMC), leading to complete loss of confidentiality, integrity, and availability of the managed server hardware. This vulnerability affects downstream vendors integrating OpenBMC, impacting enterprise, cloud, and high-performance computing environments where IPMI is exposed to the management network.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all servers running OpenBMC-based firmware within your environment using internal asset management or vulnerability scanning tools.</li>
<li>Review the advisories from your specific hardware vendors (such as NVIDIA or H3C) for firmware updates that address CVE-2026-16140.</li>
<li>Apply the vendor-provided firmware patches to all vulnerable BMCs immediately.</li>
<li>Restrict access to the IPMI/BMC management network to authorized management subnets and jump hosts to limit exposure.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>ipmi</category><category>openbmc</category></item></channel></rss>