Arbitrary Code Execution Vulnerability in IBM Power Systems Firmware
CVE-2026-16930

8.2HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-16930?

IBM Power Systems Firmware versions FW1120.00, FW1110.00 to FW1110.30, and FW1060.00 to FW1060.80 are prone to a significant vulnerability that affects the interface between the Baseboard Management Controller (BMC) or the Firmware Service Processor (FSP) and the host system. An attacker with either service account or root access to the BMC/FSP can leverage this flaw to execute arbitrary code on the host system, leading to complete control over the system and all connected partitions. This extensive access can severely undermine the confidentiality, integrity, and availability of the affected systems.

Affected Version(s)

Power Systems Firmware FW1120.00

Power Systems Firmware FW1110.00

Power Systems Firmware FW1060.00

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.