Local Data Decryption Flaw in IBM PowerVM Hypervisor
CVE-2026-4937
5.3MEDIUM
What is CVE-2026-4937?
A vulnerability in IBM PowerVM Hypervisor allows a local attacker with administrative privileges to decrypt sensitive data. This issue arises from certain hypervisor calls that utilize less entropy than required, potentially exposing encrypted information. Affected firmware versions include FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2. Users are advised to apply the recommended patches to mitigate this risk.
Affected Version(s)
PowerVM Hypervisor FW1110.00
PowerVM Hypervisor FW1060.00
PowerVM Hypervisor FW950.00