IBM PowerVM Novalink API Misconfig Enables Unauthorized Ops (2.3)
CVE-2026-14971 Published on July 17, 2026
This PowerVM Novalink update is being released to address
IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions.
Vulnerability Analysis
CVE-2026-14971 can be exploited with local system access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be low. considered to have a small impact on confidentiality and integrity and availability.
Weakness Type
Configuration
Weaknesses in this category are typically introduced during the configuration of the software.
Products Associated with CVE-2026-14971
Want to know whenever a new CVE is published for IBM Powervm Novalink? stack.watch will email you.
Affected Versions
IBM PowerVM Novalink:- Version 2.2.02.2.12.2.1.1 is affected.
- Version 2.3.02.3.0.12.3.12.3.2 is affected.