← All CVEs

CVE-2026-12943

critical · 9.8

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

9.8
CVSS
1.0%
EPSS (exploit prob.)
62nd
EPSS percentile
2026-07-30
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
ibmhardware_management_console>= 10.3.1050.0, < 10.3.1064.1
ibmhardware_management_console>= 11.1.1110.0, < 11.1.1112.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-12943