Service Processor Mailbox Interface Vulnerability in IBM Power Systems Firmware
CVE-2026-17100

8.2HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-17100?

A vulnerability exists within the service processor mailbox interface of IBM Power Systems firmware, affecting various versions. An authenticated attacker with service-level access to the Baseboard Management Controller (BMC) or Firmware Service Processor (FSP) can exploit this weakness, potentially executing arbitrary code in the host firmware runtime. This exploitation could lead to unauthorized control over the managed system, ultimately impacting its confidentiality, integrity, and availability.

Affected Version(s)

Power Systems Firmware FW1120.00

Power Systems Firmware FW1110.00

Power Systems Firmware FW1060.00

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.