{"id":"CVE-2026-16140","summary":"OpenBMC IPMI Privilege Escalation via Retargeted RAKP 1","details":"OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation without re-authentication.","modified":"2026-10-08T02:50:37.988562749Z","published":"2026-09-15T13:57:19.310Z","database_specific":{"cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16140.json","cna_assigner":"runZero"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16140.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16140"},{"type":"ADVISORY","url":"https://www.runzero.com/advisories/openbmc-ipmi-privsec-rakp-cve-2026-16140/"},{"type":"PACKAGE","url":"https://github.com/openbmc/phosphor-net-ipmid"},{"type":"ARTICLE","url":"https://www.runzero.com/blog/lights-out-exposed/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openbmc/phosphor-net-ipmid","events":[{"introduced":"0"},{"last_affected":"ba6efc502e6b1fabb8ed1ca677ae5eedd64b6361"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16140.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}