Improper Control of Format Strings in IBM PowerVM Hypervisor
CVE-2026-15961

5.2MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-15961?

IBM PowerVM Hypervisor versions FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 are vulnerable to an issue that could allow a local attacker to exploit improper control of format strings. This vulnerability may lead to unauthorized access to sensitive information or result in a denial of service, impacting system availability and integrity. It is essential for users of the affected products to review the vendor's advisory for mitigation steps and patches.

Affected Version(s)

PowerVM Hypervisor FW1120.00

PowerVM Hypervisor FW1110.00

PowerVM Hypervisor FW1060.00

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.