CVE-2026-16938 - Power System Missing Authorization
Brief
CVE ID : CVE-2026-16938
Published : Aug. 19, 2026, 6:48 p. m.
- 20 minutes ago
Description : IBM Server Firmware FW1120. 00, FW1110. 00 through FW1110. 30, FW1060. 00 through FW1060. 80, and FW950. 00 through FW950. H2 is affected by a vulnerability in access controls over privileged system configuration operations on the FSP.
An attacker with authenticated administrator-level access to the FSP can place the managed system into a non-production operational mode, allowing certain system components to be disabled. This condition persists across FSP resets and requires explicit operator intervention — clearing the affected configuration — to restore normal operation.
Successful exploitation results in an availability impact to the managed system.
Severity: 6.9
- MEDIUM
