CVE-2026-16938

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access controls over privileged system configuration operations on the FSP. An attacker with authenticated administrator-level access to the FSP can place the managed system into a non-production operational mode, allowing certain system components to be disabled. This condition persists across FSP resets and requires explicit operator intervention — clearing the affected configuration — to restore normal operation. Successful exploitation results in an availability impact to the managed system.
References
Link Resource
https://www.ibm.com/support/pages/node/7283896 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ibm:power_system_e1080_\(9080-hex\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e1080_\(9080-hex\):-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:ibm:power_system_e1180_\(9080-heu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1180_\(9080-heu\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e1180_\(9080-heu\):-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ibm:power_system_s922_\(9009-22g\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s922_\(9009-22g\):-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ibm:power_system_h922_\(9223-22s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_h922_\(9223-22s\):-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ibm:power_system_s914_\(9009-41g\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s914_\(9009-41g\):-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ibm:power_system_s924_\(9009-42g\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s924_\(9009-42g\):-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ibm:power_system_h924_\(9223-42s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_h924_\(9223-42s\):-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ibm:power_system_e950_\(9040-mr9\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e950_\(9040-mr9\):-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:ibm:power_system_e980_\(9080-m9s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e980_\(9080-m9s\):-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-19 19:17

Updated : 2026-08-25 15:56


NVD link : CVE-2026-16938

Mitre link : CVE-2026-16938

CVE.ORG link : CVE-2026-16938


JSON object : View

Products Affected

ibm

  • power_system_e980_\(9080-m9s\)
  • power_system_s924_\(9009-42g\)_firmware
  • power_system_s914_\(9009-41g\)
  • power_system_s922_\(9009-22g\)_firmware
  • power_system_s914_\(9009-41g\)_firmware
  • power_system_h924_\(9223-42s\)_firmware
  • power_system_s922_\(9009-22g\)
  • power_system_e980_\(9080-m9s\)_firmware
  • power_system_h922_\(9223-22s\)_firmware
  • power_system_e950_\(9040-mr9\)
  • power_system_h924_\(9223-42s\)
  • power_system_e1180_\(9080-heu\)_firmware
  • power_system_e1180_\(9080-heu\)
  • power_system_e950_\(9040-mr9\)_firmware
  • power_system_s924_\(9009-42g\)
  • power_system_e1080_\(9080-hex\)_firmware
  • power_system_e1080_\(9080-hex\)
  • power_system_h922_\(9223-22s\)
CWE
CWE-862

Missing Authorization