Junglewise Threat Intelligence

CVE-2026-18848: IBM Power Systems Firmware CSRF in ASMI web interface

CVE-2026-18848 · Severity: high · CVSS 8.3 · Published 2026-08-19

Technologies: IBM Power Systems Firmware. Vendors: IBM.

Executive brief

IBM Power Systems Firmware contains a cross-site request forgery (CSRF) vulnerability in the ASMI (Advanced System Management Interface) web console used by administrators to manage Power Systems servers. An attacker can trick a logged-in administrator into visiting a malicious web page and silently perform unauthorized administrative actions on the server, potentially compromising the confidentiality, integrity, and availability of the entire managed system.

Technical details

The vulnerability is a cross-site request forgery (CSRF, CWE-352) in the ASMI web interface of IBM Power Systems Firmware. An attacker can craft a web page that, when visited by an authenticated ASMI administrator, performs unauthorized administrative actions on the Flexible Service Processor (FSP) without the administrator's knowledge or consent. The attack requires user interaction (luring the admin to visit the crafted page) and network access, but no additional authentication. Successful exploitation results in unauthorized administrative access and can impact system confidentiality, integrity, and availability. Patches are available through FW1120.01, FW1110.31, FW1060.81, or FW950.H3 depending on the firmware version and system model.

Affected products

  • IBM Power Systems Firmware FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80, FW950.00-FW950.H2

Timeline

  • 2026-08-15: disclosed: Initial publication of security bulletin

References

Related threats