Arbitrary Code Execution Vulnerability in IBM Power Systems Firmware
CVE-2026-17494

8.2HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-17494?

IBM Power Systems Firmware versions FW1120.00, and FW1110.00 through FW1110.30 are vulnerable to an arbitrary code execution flaw. This vulnerability arises from a security weakness in the interface between the Baseboard Management Controller (BMC) and the host system. An attacker with access to the BMC could potentially execute specially-crafted commands, enabling them to run arbitrary code on the host. This results in complete control over the affected host system and any hosted partitions, thereby compromising system confidentiality, integrity, and availability. Organizations using these firmware versions should promptly review the advisory and apply necessary patches.

Affected Version(s)

Power Systems Firmware FW1120.00

Power Systems Firmware FW1110.00

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.