Arbitrary Code Execution Vulnerability in IBM Power Systems Firmware
CVE-2026-17494
8.2HIGH
What is CVE-2026-17494?
IBM Power Systems Firmware versions FW1120.00, and FW1110.00 through FW1110.30 are vulnerable to an arbitrary code execution flaw. This vulnerability arises from a security weakness in the interface between the Baseboard Management Controller (BMC) and the host system. An attacker with access to the BMC could potentially execute specially-crafted commands, enabling them to run arbitrary code on the host. This results in complete control over the affected host system and any hosted partitions, thereby compromising system confidentiality, integrity, and availability. Organizations using these firmware versions should promptly review the advisory and apply necessary patches.
Affected Version(s)
Power Systems Firmware FW1120.00
Power Systems Firmware FW1110.00