SECURITYCRITICALCVE-2026-79820

CVE-2026-79820: HPE Integrated Lights-Out 7 Remote User Validation Failure

Critical CVSS 9.0 authentication bypass in HPE iLO 7 firmware could let remote attackers gain full administrative control of affected BMCs.

Dylan H.

Security Team

October 6, 2026
6 min read
CVE-2026-79820: HPE Integrated Lights-Out 7 Remote User Validation Failure

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • HPE Integrated Lights-Out (iLO) 7 firmware

Overview

HPE Integrated Lights-Out (iLO) is Hewlett Packard Enterprise's out-of-band server management interface — a Baseboard Management Controller (BMC) built into ProLiant and Apollo servers that gives administrators remote access to power control, virtual media, console redirection, and hardware health, independent of whatever operating system is (or isn't) running on the host.

CVE-2026-79820 is described by its authoritative source record as a "remote user validation failure vulnerability" in HPE iLO 7 firmware. In practice, that description points to a failure in how the management interface verifies the identity of a remote user before granting access. The flaw carries a CVSS v3.1 base score of 9.0 (Critical), with a published vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H — network-exploitable, no privileges or user interaction required, and full impact to confidentiality, integrity, and availability.

A vulnerability in a BMC is especially severe because the BMC operates at a layer below and independent of the host operating system. It has its own network interface, its own firmware, and hardware-level control over the server — including power state, boot media, and (on some platforms) direct memory access. An attacker who defeats user validation on iLO doesn't just get a foothold in an application; they potentially get administrative control of the physical machine itself, persistent across OS reinstalls and largely invisible to host-based security tooling.


Technical Details

FieldValue
CVE IDCVE-2026-79820
SeverityCritical — CVSS v3.1 base score 9.0
CWECWE-287 (Improper Authentication) — the better fit for a "remote user validation failure," since the issue described is a breakdown in verifying a user's identity/credentials outright, rather than an attacker spoofing a trusted identity, which would point more toward CWE-290 (Authentication Bypass by Spoofing)
Attack VectorNetwork (AV:N)
Attack ComplexityHigh (AC:H), per the published CVSS vector
AuthenticationNone required (PR:N)
Privileges RequiredNone
User InteractionNone
ScopeChanged (S:C) — consistent with a BMC flaw, since a successful attack can affect resources (the host server) outside the security scope of the vulnerable iLO component itself
ImpactConfidentiality, Integrity, and Availability all rated High
Affected ComponentHPE iLO 7 firmware. Third-party CVE trackers list firmware version 1.25.00 as affected, but this has not been independently verified against HPE's primary advisory
Fixed VersionNot independently confirmed at publication time. Refer to the official HPE Security Bulletin for iLO 7 for the patched firmware build — third-party aggregators cite HPE reference hpesbhf05163en_us, but that page could not be directly loaded during research, so treat the exact fix version as unconfirmed until checked against HPE's support portal

How It Works

The public record does not include exploit-level technical detail, and none should be assumed or implied here. In general terms, a "remote user validation failure" in a BMC management interface is the kind of flaw that arises when a component — commonly the web UI login flow, a session/token check, or the Redfish API used for programmatic management — fails to correctly verify that a request genuinely belongs to an authenticated, authorized user before acting on it. Depending on exactly where the check breaks down, this class of flaw can let a remote, unauthenticated attacker bypass login entirely or ride past a session check to reach administrative functionality on the out-of-band management plane.

Because the CVSS vector for this CVE records PR:N and UI:N (no privileges or user interaction needed) alongside AC:H (high attack complexity), the practical read is that exploitation does not require an existing account or any action from a legitimate user, but likely depends on satisfying some non-trivial preconditions or timing/sequencing to trigger the validation failure. Again, this is a description of the general vulnerability class implied by the CVSS metrics and CWE mapping — not a confirmed, vendor-disclosed exploitation technique.


Impact Assessment

Who Is At Risk

Any organization running HPE ProLiant, Apollo, or other servers with iLO 7 is potentially exposed, with risk scaling sharply based on network exposure. Organizations with iLO interfaces reachable from a general internal management network are at risk; those with iLO reachable from the broader internet — whether through misconfiguration, a forgotten port-forward, or an intentional but unhardened remote-access setup — are at the highest risk, since this vulnerability requires no credentials and no user interaction to exploit over the network.

Potential Attack Chains

  1. Discovery of an exposed iLO 7 interface, typically through internet-wide scanning for the iLO web UI or Redfish API, or internal network reconnaissance.
  2. Exploitation of the remote user validation failure to bypass authentication on the management interface.
  3. Administrative access to the BMC, independent of any host operating system credentials or controls.
  4. Full control of the underlying server hardware — including mounting virtual media, forcing power cycles or shutdowns, and potentially establishing firmware-level persistence that survives OS reinstallation.

Mitigation

Immediate Actions

  • Apply the HPE firmware update for iLO 7 once confirmed, per the official HPE Security Bulletin — do not rely on this article for the exact patched build number.
  • Ensure iLO interfaces are never exposed directly to the public internet, regardless of patch status.

Detection Opportunities

  • Review iLO access and authentication logs for unexpected or anomalous login/session events, particularly successful administrative actions with no corresponding legitimate user activity.

Defence-in-Depth

  • Isolate BMC/management interfaces (iLO, and equivalents on other vendors' hardware) on a dedicated, access-controlled management VLAN, separate from general corporate or production networks.
  • Enforce strong, unique iLO credentials, and enable multi-factor authentication where the platform supports it.
  • Restrict network reachability to iLO interfaces to a hardened jump host or bastion, rather than allowing direct access from end-user or general server subnets.

Discovery & Disclosure

CVE-2026-79820 was published via NVD on 2026-10-05. Public CVE record metadata indicates the identifier was reserved on 2026-08-25, ahead of publication. No discoverer or credited researcher was identified in the public sources checked for this article — if HPE's bulletin credits a specific individual or organization, that detail was not independently verifiable at the time of writing. As of publication, this CVE is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and no public proof-of-concept exploit code was identified; both should be treated as unconfirmed rather than definitively absent, since vulnerability intelligence on a CVE this recent continues to evolve.


References