Junglewise Threat Intelligence

CVE-2026-16938: IBM Power Systems Firmware missing authorization in FSP configuration

CVE-2026-16938 · Severity: medium · CVSS 6.9 · Published 2026-08-19

Technologies: IBM Power Systems Firmware. Vendors: IBM.

Executive brief

IBM Power Systems firmware used to manage enterprise servers contains a flaw in access controls that allows authenticated administrators to place the system into a non-production mode, disabling critical components. This misconfiguration persists across system restarts and can only be cleared manually by an operator, causing potential service outages that impact business continuity and system availability.

Technical details

The vulnerability is a missing authorization flaw (CWE-862) in the Flexible Service Processor (FSP) firmware that fails to properly enforce access controls over privileged system configuration operations. An attacker with authenticated administrator-level credentials to the FSP can place the managed system into a non-production operational mode, selectively disabling system components. The vulnerability requires administrator authentication and adjacent network access to the FSP interface. Successful exploitation causes high availability impact, as the disabled state persists across FSP resets and requires manual operator intervention to clear the affected configuration. Patches are available: FW1120.01 or newer for Power 11, FW1060.81 or newer for Power 10, and FW950.H3 or newer for Power 9 systems.

Affected products

  • IBM Power Systems Firmware FW1120.00, FW1110.00–FW1110.30, FW1060.00–FW1060.80, FW950.00–FW950.H2

Timeline

  • 2026-08-15: disclosed: Initial publication of security bulletin
  • 2026-08-19: patched: Patches released: FW1120.01, FW1110.31, FW1060.81, FW950.H3

References

Related threats