Access Control Issues in IBM Power Systems Firmware
CVE-2026-16938
6.9MEDIUM
What is CVE-2026-16938?
IBM Power Systems Firmware is compromised by a vulnerability that affects the access control mechanisms over privileged system configuration operations on the Flexible Service Processor (FSP). An attacker with authenticated administrator-level access to the FSP can manipulate the managed system's operational mode, potentially disrupting availability by disabling critical components. This misconfiguration remains persistent across system resets, necessitating manual operator intervention to revert to normal operations, thereby posing a significant risk to system availability and operational integrity.
Affected Version(s)
Power Systems Firmware FW1120.00
Power Systems Firmware FW1110.00
Power Systems Firmware FW1060.00