What is CVE-2026-16938?
CVE-2026-16938 is a vulnerability in IBM Power Systems FSP regarding inadequate access controls over privileged system configuration operations. An attacker with authenticated administrator-level access could exploit this to perform unauthorized system configuration changes. Affected firmware versions should be updated immediately.
Azərbaycanca: CVE-2026-16938, IBM Power Systems FSP (Flexible Service Processor) platformasında imtiyazlı sistem konfiqurasiya əməliyyatları üzərində zəif giriş nəzarəti zəifliyidir. Bu problem, autentifikasiya olunmuş administrator səviyyəli girişə malik təcavüzkarın sistem konfiqurasiyasına icazəsiz müdaxilə etməsinə imkan yarada bilər. Təsirə məruz qalan firmware versiyalarına sahib istifadəçilər dərhal yeniləmə tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: IBM
FAQ2
What level of access must an attacker have to exploit CVE-2026-16938?
The attacker must have authenticated administrator-level access.
Which platform is affected by CVE-2026-16938?
This vulnerability affects the IBM Power Systems FSP (Flexible Service Processor) platform.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.