{"api_version":"1","generated_at":"2026-09-14T20:01:01+00:00","cve":"CVE-2026-16938","urls":{"html":"https://cve.report/CVE-2026-16938","api":"https://cve.report/api/cve/CVE-2026-16938.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-16938","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-16938"},"summary":{"title":"Power System Missing Authorization","description":"IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access controls over privileged system configuration operations on the FSP. An attacker with authenticated administrator-level access to the FSP can place the managed system into a non-production operational mode, allowing certain system components to be disabled. This condition persists across FSP resets and requires explicit operator intervention — clearing the affected configuration — to restore normal operation. Successful exploitation results in an availability impact to the managed system.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-08-19 19:17:10","updated_at":"2026-08-25 15:56:28"},"problem_types":["CWE-862","CWE-862 CWE-862 Missing Authorization"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"6.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H","data":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":6.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7283896","name":"https://www.ibm.com/support/pages/node/7283896","refsource":"psirt@us.ibm.com","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16938","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16938","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Power Systems Firmware","version":"affected FW1120.00","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Power Systems Firmware","version":"affected FW1110.00 FW1110.30 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Power Systems Firmware","version":"affected FW1060.00 FW1060.80 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Power Systems Firmware","version":"affected FW950.00 FW950.H2 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Customers with the products below should install FW1120.01(1120_167), FW1110.31(1110_134), or newer to remediate this vulnerability.\n\n\n\nPower 11\n1) IBM Power System E1180 (9080-HEU)\n\n\n\nCustomers with the products below should install FW1060.81(1060_184), or newer to remediate this vulnerability.\n\n\n\nPower 10\n1) IBM Power System E1080 (9080-HEX)\n\n\n\nCustomers with the products below should install FW950.H3(950_230), or newer to remediate this vulnerability.\n\n\n\nPower9\n1) IBM Power System S922 (9009-22G)\n2) IBM Power System H922 (9223-22S)\n3) IBM Power System S914 (9009-41G)\n4) IBM Power System S924 (9009-42G)\n5) IBM Power System H924 (9223-42S)\n6) IBM Power System E950 (9040-MR9)\n7) IBM Power System E980 (9080-M9S)\n\n\n\nThe images mentioned above can be located at IBM Fix Central :  https://www.ibm.com/support/fixcentral/","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"Protect access to the FSP's administrative interface.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2026","cve_id":"16938","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ibm","cpe5":"power_system_e1080_\\(9080-hex\\)","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"power_system_e1080_\\(9080-hex\\)_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ibm","cpe5":"power_system_e1180_\\(9080-heu\\)","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"power_system_e1180_\\(9080-heu\\)_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"power_system_e1180_\\(9080-heu\\)_firmware","cpe6":"fw1120.00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ibm","cpe5":"power_system_e950_\\(9040-mr9\\)","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"power_system_e950_\\(9040-mr9\\)_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ibm","cpe5":"power_system_e980_\\(9080-m9s\\)","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"power_system_e980_\\(9080-m9s\\)_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ibm","cpe5":"power_system_h922_\\(9223-22s\\)","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"power_system_h922_\\(9223-22s\\)_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ibm","cpe5":"power_system_h924_\\(9223-42s\\)","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"power_system_h924_\\(9223-42s\\)_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ibm","cpe5":"power_system_s914_\\(9009-41g\\)","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"power_system_s914_\\(9009-41g\\)_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ibm","cpe5":"power_system_s922_\\(9009-22g\\)","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"power_system_s922_\\(9009-22g\\)_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"ibm","cpe5":"power_system_s924_\\(9009-42g\\)","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"16938","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"power_system_s924_\\(9009-42g\\)_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"16938","cve":"CVE-2026-16938","epss":"0.001380000","percentile":"0.034120000","score_date":"2026-08-25","updated_at":"2026-08-26 00:12:15"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-16938","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-20T15:18:49.285398Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-20T15:26:35.014Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*","cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*","cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*","cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*","cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*","cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*","cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*"],"product":"Power Systems Firmware","vendor":"IBM","versions":[{"status":"affected","version":"FW1120.00"},{"lessThanOrEqual":"FW1110.30","status":"affected","version":"FW1110.00","versionType":"semver"},{"lessThanOrEqual":"FW1060.80","status":"affected","version":"FW1060.00","versionType":"semver"},{"lessThanOrEqual":"FW950.H2","status":"affected","version":"FW950.00","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access controls over privileged system configuration operations on the FSP. An attacker with authenticated administrator-level access to the FSP can place the managed system into a non-production operational mode, allowing certain system components to be disabled. This condition persists across FSP resets and requires explicit operator intervention — clearing the affected configuration — to restore normal operation. Successful exploitation results in an availability impact to the managed system.</p>"}],"value":"IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access controls over privileged system configuration operations on the FSP. An attacker with authenticated administrator-level access to the FSP can place the managed system into a non-production operational mode, allowing certain system components to be disabled. This condition persists across FSP resets and requires explicit operator intervention — clearing the affected configuration — to restore normal operation. Successful exploitation results in an availability impact to the managed system."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":6.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-19T18:59:17.561Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7283896"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Customers with the products below should install FW1120.01(1120_167), FW1110.31(1110_134), or newer to remediate this vulnerability.</p><p>Power 11<br/>1) IBM Power System E1180 (9080-HEU)</p><p>Customers with the products below should install FW1060.81(1060_184), or newer to remediate this vulnerability.</p><p>Power 10<br/>1) IBM Power System E1080 (9080-HEX)</p><p>Customers with the products below should install FW950.H3(950_230), or newer to remediate this vulnerability.</p><p>Power9<br/>1) IBM Power System S922 (9009-22G)<br/>2) IBM Power System H922 (9223-22S)<br/>3) IBM Power System S914 (9009-41G)<br/>4) IBM Power System S924 (9009-42G)<br/>5) IBM Power System H924 (9223-42S)<br/>6) IBM Power System E950 (9040-MR9)<br/>7) IBM Power System E980 (9080-M9S)</p><p>The images mentioned above can be located at IBM Fix Central : <a href=\"https://www.ibm.com/support/fixcentral/\" rel=\"nofollow\">https://www.ibm.com/support/fixcentral/</a></p>"}],"value":"Customers with the products below should install FW1120.01(1120_167), FW1110.31(1110_134), or newer to remediate this vulnerability.\n\n\n\nPower 11\n1) IBM Power System E1180 (9080-HEU)\n\n\n\nCustomers with the products below should install FW1060.81(1060_184), or newer to remediate this vulnerability.\n\n\n\nPower 10\n1) IBM Power System E1080 (9080-HEX)\n\n\n\nCustomers with the products below should install FW950.H3(950_230), or newer to remediate this vulnerability.\n\n\n\nPower9\n1) IBM Power System S922 (9009-22G)\n2) IBM Power System H922 (9223-22S)\n3) IBM Power System S914 (9009-41G)\n4) IBM Power System S924 (9009-42G)\n5) IBM Power System H924 (9223-42S)\n6) IBM Power System E950 (9040-MR9)\n7) IBM Power System E980 (9080-M9S)\n\n\n\nThe images mentioned above can be located at IBM Fix Central :  https://www.ibm.com/support/fixcentral/"}],"title":"Power System Missing Authorization","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Protect access to the FSP's administrative interface.</p>"}],"value":"Protect access to the FSP's administrative interface."}]}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-16938","datePublished":"2026-08-19T18:48:32.835Z","dateReserved":"2026-07-24T07:44:31.605Z","dateUpdated":"2026-08-20T15:26:35.014Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-19 19:17:10","lastModifiedDate":"2026-08-25 15:56:28","problem_types":["CWE-862","CWE-862 CWE-862 Missing Authorization"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":1.7,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-20T15:18:49.285398Z","id":"CVE-2026-16938","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:power_system_e1080_\\(9080-hex\\)_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"fw1060.00","versionEndExcluding":"fw1060.81","matchCriteriaId":"AA6D803F-DD5C-49A7-BE93-68981C124C69"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ibm:power_system_e1080_\\(9080-hex\\):-:*:*:*:*:*:*:*","matchCriteriaId":"DF85251B-E02C-4293-98F0-D331BF51CAC4"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:power_system_e1180_\\(9080-heu\\)_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"fw1110.00","versionEndExcluding":"fw1110.31","matchCriteriaId":"E8049F52-227B-4CCA-B059-5821F9B41C95"},{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:power_system_e1180_\\(9080-heu\\)_firmware:fw1120.00:*:*:*:*:*:*:*","matchCriteriaId":"F518B3DD-3F25-4581-9103-6CD4D8DA54C7"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ibm:power_system_e1180_\\(9080-heu\\):-:*:*:*:*:*:*:*","matchCriteriaId":"8BD4FC49-8120-4D4B-906A-1B6FA6B30FA2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:power_system_s922_\\(9009-22g\\)_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"fw950.00","versionEndExcluding":"fw950.h3","matchCriteriaId":"0C406C5A-454C-4454-861F-80E629B68418"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ibm:power_system_s922_\\(9009-22g\\):-:*:*:*:*:*:*:*","matchCriteriaId":"95E5E77F-A5BB-46E7-B6B6-B02F242DE829"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:power_system_h922_\\(9223-22s\\)_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"fw950.00","versionEndExcluding":"fw950.h3","matchCriteriaId":"FBE7D8B3-902D-4CD1-9F31-454E293A79B3"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ibm:power_system_h922_\\(9223-22s\\):-:*:*:*:*:*:*:*","matchCriteriaId":"E7851003-8D6B-4FE8-87D7-BE968E85E448"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:power_system_s914_\\(9009-41g\\)_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"fw950.00","versionEndExcluding":"fw950.h3","matchCriteriaId":"CD77C09F-AF62-4CD8-B64C-CDF50D696648"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ibm:power_system_s914_\\(9009-41g\\):-:*:*:*:*:*:*:*","matchCriteriaId":"003F591A-ACCD-497E-BF8A-DE090321D778"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:power_system_s924_\\(9009-42g\\)_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"fw950.00","versionEndExcluding":"fw950.h3","matchCriteriaId":"54831AF9-D748-4649-A0ED-896341845BCD"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ibm:power_system_s924_\\(9009-42g\\):-:*:*:*:*:*:*:*","matchCriteriaId":"4038C5DB-DF9C-4661-9590-F6A0CD4D15D5"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:power_system_h924_\\(9223-42s\\)_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"fw950.00","versionEndExcluding":"fw950.h3","matchCriteriaId":"64FD3222-EEFD-4533-A088-B05F04E0831D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ibm:power_system_h924_\\(9223-42s\\):-:*:*:*:*:*:*:*","matchCriteriaId":"C2F0E93A-26F0-4914-8A31-3C86E64D5B8A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:power_system_e950_\\(9040-mr9\\)_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"fw950.00","versionEndExcluding":"fw950.h3","matchCriteriaId":"C99CF91B-A98D-4795-A8AE-998713989ABE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ibm:power_system_e950_\\(9040-mr9\\):-:*:*:*:*:*:*:*","matchCriteriaId":"9FF58E5C-0A54-4F2F-A426-0BFD1EACE991"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:power_system_e980_\\(9080-m9s\\)_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"fw950.00","versionEndExcluding":"fw950.h3","matchCriteriaId":"272B1267-28AC-4BDB-93C4-9804DBE240E0"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ibm:power_system_e980_\\(9080-m9s\\):-:*:*:*:*:*:*:*","matchCriteriaId":"9BE56BD8-DB0F-4151-9428-42F1B6452D99"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"16938","Ordinal":"1","Title":"Power System Missing Authorization","CVE":"CVE-2026-16938","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"16938","Ordinal":"1","NoteData":"IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access controls over privileged system configuration operations on the FSP. An attacker with authenticated administrator-level access to the FSP can place the managed system into a non-production operational mode, allowing certain system components to be disabled. This condition persists across FSP resets and requires explicit operator intervention — clearing the affected configuration — to restore normal operation. Successful exploitation results in an availability impact to the managed system.","Type":"Description","Title":"Power System Missing Authorization"}]}}}