Vulnerability in IBM PowerVM Hypervisor Affects Partition Firmware Boot Configuration
CVE-2026-17503

5.1MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
24 September 2026

What is CVE-2026-17503?

IBM PowerVM Hypervisor versions FW1120.00 to FW1120.01, FW1110.00 to FW1110.31, FW1060.00 to FW1060.81, and FW950.00 to FW950.H3 are susceptible to a vulnerability where an attacker with root access can modify the partition firmware's nvram settings. This manipulation leads to a boot failure of the affected partition, which will require manual configuration restoration by an operator to regain normal operations. The exploitation of this vulnerability poses risks to the integrity and availability of the system.

Affected Version(s)

PowerVM Hypervisor FW1120.00

PowerVM Hypervisor FW1110.00

PowerVM Hypervisor FW1060.00

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.