Local Data Decryption Flaw in IBM PowerVM Hypervisor
CVE-2026-4937

5.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-4937?

A vulnerability in IBM PowerVM Hypervisor allows a local attacker with administrative privileges to decrypt sensitive data. This issue arises from certain hypervisor calls that utilize less entropy than required, potentially exposing encrypted information. Affected firmware versions include FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2. Users are advised to apply the recommended patches to mitigate this risk.

Affected Version(s)

PowerVM Hypervisor FW1110.00

PowerVM Hypervisor FW1060.00

PowerVM Hypervisor FW950.00

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.