What is CVE-2026-17494?
A vulnerability exists in the interface between the BMC and the host system in IBM Power Systems Firmware versions FW1120.00 and FW1110.00 through FW1110.30. An attacker with service access to the BMC can send a specially crafted command to execute arbitrary code on the host system. Applying firmware updates is recommended for affected systems.
Azərbaycanca: IBM Power Systems aparat proqram təminatında (FW1120.00 və FW1110.00-dən FW1110.30-a qədər) BMC ilə host sistem arasındakı interfeysdə boşluq aşkarlanıb. BMC-yə xidməti girişi olan hücumçu xüsusi hazırlanmış əmr göndərərək host sistemdə ixtiyari kod icra edə bilər. Təsirə məruz qalan sistemlərdə firmware yeniləməsinin tətbiqi tövsiyə olunur.
Related CVEs
link basis: shared vendor: IBM
FAQ2
What level of access does an attacker need to exploit CVE-2026-17494?
The attacker must have service access to the BMC.
What is the potential impact if this vulnerability is successfully exploited?
Arbitrary code execution on the host system is possible.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.