Code Execution Vulnerability in IBM Power Systems Firmware
CVE-2026-19234

8.2HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-19234?

The IBM Power Systems Firmware suffers from a vulnerability in the boot process image validation, allowing an authenticated attacker with service access to manipulate the firmware. By supplying a specially crafted update image, attackers can execute arbitrary code on the affected host. This vulnerability raises significant concerns regarding the confidentiality, integrity, and availability of the systems involved, as successful exploitation could lead to unauthorized access and control.

Affected Version(s)

Power Systems Firmware FW1120.00

Power Systems Firmware FW1110.00

Power Systems Firmware FW1060.00

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.