What is CVE-2026-18848?
A vulnerability exists in the ASMI web interface of IBM Power Systems Firmware. An attacker can potentially compromise the system by luring a logged-in ASMI administrator to visit a crafted web page under specific conditions. Administrators should exercise caution and monitor for firmware updates.
Azərbaycanca: IBM Power Systems proqram təminatının ASMI web interfeysində zəiflik aşkar edilib. Təcavüzkar, xüsusi hazırlanmış veb-səhifəyə keçid edən autentifikasiya olunmuş ASMI administratorunu tələyə salaraq müəyyən şərtlər altında sistemi ələ keçirə bilər. Təsirə məruz qalmamaq üçün administratorlar ehtiyatlı olmalı və proqram təminatı yeniləmələrini izləməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: IBM
FAQ2
Through which interface can the CVE-2026-18848 vulnerability be exploited?
This vulnerability exists within the ASMI web interface of IBM Power Systems Firmware.
What action must a logged-in ASMI administrator take for an attacker to exploit CVE-2026-18848?
The attacker can lure a logged-in ASMI administrator to visit a crafted web page.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.