{"api_version":"1","generated_at":"2026-07-30T20:38:04+00:00","cve":"CVE-2026-12943","urls":{"html":"https://cve.report/CVE-2026-12943","api":"https://cve.report/api/cve/CVE-2026-12943.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-12943","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-12943"},"summary":{"title":"This Power Hardware Management Console update is being released to address","description":"IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-07-30 19:17:05","updated_at":"2026-07-30 19:31:02"},"problem_types":["CWE-78","CWE-78 CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7278667","name":"https://www.ibm.com/support/pages/node/7278667","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-12943","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12943","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"HMC V10.3.1050.0","version":"affected 10.3.1050.0 10.3.1064.0 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"HMC V11.1.1110.0","version":"affected 11.1.1110.0 11.1.1112.0 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly recommends addressing the vulnerability now. The following fixes are available on IBM Fix Central at:\n\n\n\nV10R3\n\n\n\n https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~9100HMCppc&release=V10R3&platform=All \n\n\n\n https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~vHMC&release=V10R3&platform=All \n\n\n\nV11R1\n\n\n\n https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~9100HMCppc&release=V11R1&platform=All \n\n\n\n https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~vHMC&release=V11R1&platform=All \n\n\n\n\n\n\n\n\n\nProduct\n\nAffected Version(s)\n\nVRMF\n\nAPAR\n\nRemediation/Fix\n\nPower HMC\n\nV10.3.1050.0 - V10.3.1064.0\n\nV10.3.1064.1 x86\n\n\n\nMB04527\n\n\n\nMF71762\n\nPower HMC\n\nV10.3.1050.0 - V10.3.1064.0\n\nV10.3.1064.1 ppc\n\n\n\nMB04528\n\n\n\nMF71763\n\nPower HMC\n\nV11.1.1110.0 - V11.1.1112.0\n\nV11.1.1112.1 x86\n\n\n\nMB04529\n\n\n\nMF71764 \n\n\n\n\n\nPower HMC\n\nV11.1.1110.0 - V11.1.1112.0\n\nV11.1.1112.1 ppc\n\nMB04530\n\nMF71765","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-12943","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-07-30T18:39:21.327190Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-30T18:39:35.507Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:hmc_v10310500:10.3.1050.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:hmc_v10310500:10.3.1064.0:*:*:*:*:*:*:*"],"product":"HMC V10.3.1050.0","vendor":"IBM","versions":[{"lessThanOrEqual":"10.3.1064.0","status":"affected","version":"10.3.1050.0","versionType":"semver"}]},{"cpes":["cpe:2.3:a:ibm:hmc_v11111100:11.1.1110.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:hmc_v11111100:11.1.1112.0:*:*:*:*:*:*:*"],"product":"HMC V11.1.1110.0","vendor":"IBM","versions":[{"lessThanOrEqual":"11.1.1112.0","status":"affected","version":"11.1.1110.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.</p>"}],"value":"IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-78","description":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-30T17:57:46.718Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7278667"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<div><p>IBM strongly recommends addressing the vulnerability now. The following fixes are available on IBM Fix Central at:</p><p>V10R3</p><p><a href=\"https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&amp;product=ibm~hmc~9100HMCppc&amp;release=V10R3&amp;platform=All\" rel=\"nofollow\">https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&amp;product=ibm~hmc~9100HMCppc&amp;release=V10R3&amp;platform=All</a></p><p><a href=\"https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&amp;product=ibm~hmc~vHMC&amp;release=V10R3&amp;platform=All\" rel=\"nofollow\">https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&amp;product=ibm~hmc~vHMC&amp;release=V10R3&amp;platform=All</a></p><p>V11R1</p><p><a href=\"https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&amp;product=ibm~hmc~9100HMCppc&amp;release=V11R1&amp;platform=All\" rel=\"nofollow\">https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&amp;product=ibm~hmc~9100HMCppc&amp;release=V11R1&amp;platform=All</a></p><p><a href=\"https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&amp;product=ibm~hmc~vHMC&amp;release=V11R1&amp;platform=All\" rel=\"nofollow\">https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&amp;product=ibm~hmc~vHMC&amp;release=V11R1&amp;platform=All</a></p><p></p><p></p><div><table><tbody><tr><td><div>Product</div></td><td><div>Affected Version(s)</div></td><td><div>VRMF</div></td><td><div>APAR</div></td><td><div>Remediation/Fix</div></td></tr><tr><td><div>Power HMC</div></td><td><div>V10.3.1050.0 - V10.3.1064.0</div></td><td><div>V10.3.1064.1 x86</div></td><td><p>MB04527</p></td><td><p>MF71762</p></td></tr><tr><td><div>Power HMC</div></td><td><div>V10.3.1050.0 - V10.3.1064.0</div></td><td><div>V10.3.1064.1 ppc</div></td><td><p>MB04528</p></td><td><p>MF71763</p></td></tr><tr><td><div>Power HMC</div></td><td><div>V11.1.1110.0 - V11.1.1112.0</div></td><td><div>V11.1.1112.1 x86</div></td><td><p>MB04529</p></td><td><div><div><p>MF71764 </p></div></div></td></tr><tr><td><div>Power HMC</div></td><td><div>V11.1.1110.0 - V11.1.1112.0</div></td><td><div>V11.1.1112.1 ppc</div></td><td>MB04530</td><td><div><div><p>MF71765 </p></div></div></td></tr></tbody></table></div></div><div></div><p></p>"}],"value":"IBM strongly recommends addressing the vulnerability now. The following fixes are available on IBM Fix Central at:\n\n\n\nV10R3\n\n\n\n https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~9100HMCppc&release=V10R3&platform=All \n\n\n\n https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~vHMC&release=V10R3&platform=All \n\n\n\nV11R1\n\n\n\n https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~9100HMCppc&release=V11R1&platform=All \n\n\n\n https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~vHMC&release=V11R1&platform=All \n\n\n\n\n\n\n\n\n\nProduct\n\nAffected Version(s)\n\nVRMF\n\nAPAR\n\nRemediation/Fix\n\nPower HMC\n\nV10.3.1050.0 - V10.3.1064.0\n\nV10.3.1064.1 x86\n\n\n\nMB04527\n\n\n\nMF71762\n\nPower HMC\n\nV10.3.1050.0 - V10.3.1064.0\n\nV10.3.1064.1 ppc\n\n\n\nMB04528\n\n\n\nMF71763\n\nPower HMC\n\nV11.1.1110.0 - V11.1.1112.0\n\nV11.1.1112.1 x86\n\n\n\nMB04529\n\n\n\nMF71764 \n\n\n\n\n\nPower HMC\n\nV11.1.1110.0 - V11.1.1112.0\n\nV11.1.1112.1 ppc\n\nMB04530\n\nMF71765"}],"title":"This Power Hardware Management Console update is being released to address"}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-12943","datePublished":"2026-07-30T17:57:46.718Z","dateReserved":"2026-06-22T19:55:16.119Z","dateUpdated":"2026-07-30T18:39:35.507Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-30 19:17:05","lastModifiedDate":"2026-07-30 19:31:02","problem_types":["CWE-78","CWE-78 CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T18:39:21.327190Z","id":"CVE-2026-12943","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"12943","Ordinal":"1","Title":"This Power Hardware Management Console update is being released ","CVE":"CVE-2026-12943","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"12943","Ordinal":"1","NoteData":"IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.","Type":"Description","Title":"This Power Hardware Management Console update is being released "}]}}}