Memory Access Vulnerability in IBM Power Systems Firmware
CVE-2026-16933

8.2HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-16933?

A vulnerability in IBM Power Systems Firmware affects devices by exposing critical interfaces between the Baseboard Management Controller (BMC) and the host system. This flaw allows attackers with service account or root access to the BMC/FSP to exploit memory access, enabling them to read and write arbitrary regions of the host system memory. Consequently, this breach grants complete control over the host system and all hosted partitions, posing significant threats to confidentiality, integrity, and availability of the systems involved.

Affected Version(s)

Power Systems Firmware FW1120.00

Power Systems Firmware FW1110.00

Power Systems Firmware FW1060.00

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.