interesting · Firmware — edge
HPE disclosed a pre-authentication remote validation failure in iLO 7.
Affects
HPE Integrated Lights-Out 7, the embedded management controller in HPE ProLiant Gen12 servers.
The affected range is iLO 7 firmware before 1.25.00, and exploitation requires network access but no authenticated management session.
Detail and 5 sources
The disclosure does not establish whether success yields an iLO session, Compute Ops Management impersonation, direct server controls, or some narrower effect.
Chain to watch
Reach an iLO 7 interface running firmware before 1.25.00.→↓Trigger the remote user-validation failure.→↓Determine the resulting management identity and operations.→↓The vulnerable protocol, prerequisite, granted role, and post-validation authority are missing from the retrievable material.
Unverified chainRetrieve HPESBHF05163 rev.1 or HPE’s machine-readable advisory and map the resulting authority.
Sources
ResearchCVE-2026-79820 | Remote User Validation Failure in HPE iLO 7 FirmwareCode / PoCA remote user validation failure vulnerability exists in... · CVE-2026-79820 · GitHub Advisory Database · GitHubVendorBulletin de sécurité HPE (AV26-1000) - Centre canadien pour la cybersécuritéSecondaryHPE security advisory (AV26-1000)SecondaryHPE iLO 7 remote validation failure