CVE-2026-79820
CVSS 9 CRITICAL: a remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.
Vulnerabilities & Exploits
HPE disclosed a critical authentication bypass in Integrated Lights-Out 7 (iLO 7) firmware before 1.25.00, tracked as CVE-2026-79820. INCIBE-CERT said the flaw could let a remote attacker get past user validation in HPE's out-of-band management interface.
The problem sits in the remote COM validation path: if that check fails open, the management plane can accept requests as authenticated even when the credentials are not valid. That matters because iLO sits outside the server operating system, so a compromise there can bypass the controls defenders expect from the normal network and host stack.
For teams that expose iLO on production or remote-access networks, the exposure is the management console itself, not just the machine it oversees. Once that boundary is crossed, hardware-management functions may be reachable without credentials until the firmware is fixed.
1 source · 8h ago
CVSS 9 CRITICAL: a remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.
INCIBE-CERT
Autenticación incorrecta en Integrated Lights-Out 7 de HPE
HPE ha publicado una vulnerabilidad de severidad crítica que, en caso de ser explotada, podría permiti
originalPart of the PlainSec briefing for 2026-10-06
Every edition of this story: HPE iLO 7 Bypass Exposes Remote Management