Executive brief
IBM Power Hardware Management Console (HMC), a tool used by administrators to manage IBM Power servers and virtual machines, contains a critical security flaw. An unauthenticated attacker could remotely take full control of the management system by exploiting improper input handling. This could lead to unauthorized access to managed server infrastructure, data theft, or complete service disruption.
Technical details
This vulnerability is classified as an OS Command Injection (CWE-78) within the IBM Power Hardware Management Console (HMC) and Novalink management systems. The flaw stems from improper neutralization of special elements in user-supplied input, allowing an unauthenticated attacker to inject and execute arbitrary commands via the network. Successful exploitation grants the attacker elevated privileges on the management system. IBM has released patches for affected versions V10.3.1050.0 through 10.3.1064.0 and V11.1.1110.0 through 11.1.1112.0. Security updates are available via IBM Fix Central.
Affected products
- IBM Hardware Management Console (HMC) V10 10.3.1050.0 - 10.3.1064.0
- IBM Hardware Management Console (HMC) V11 11.1.1110.0 - 11.1.1112.0
- IBM Novalink Impacted versions within Power environments
Timeline
- 2026-07-01: disclosed: Initial publication by IBM
- 2026-07-30: advisory: NVD publication date