What is CVE-2026-16930?
This vulnerability exists in the interface between the BMC/FSP and the host system within IBM Power Systems Firmware. An attacker with service account or root access to the BMC/FSP can execute arbitrary code on the host system. Updating the affected firmware to the latest version is strongly recommended.
Azərbaycanca: Bu boşluq IBM Power Systems Firmware-də BMC/FSP ilə host sistem arasındakı interfeysdə aşkarlanıb. BMC/FSP-yə xidmət hesabı və ya kök (root) girişi olan hücumçu host sistemində ixtiyari kod icra edə bilər. Təsirə məruz qalan sistemlərin proqram təminatını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: IBM
FAQ2
What privileged access does an attacker need to exploit CVE-2026-16930?
An attacker must have service account or root access to the BMC/FSP on IBM Power Systems.
What can happen if this vulnerability is successfully exploited?
An attacker can execute arbitrary code on the host system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.