IBM PowerVM Novalink API Misconfig Enables Unauthorized Ops (2.3)
CVE-2026-14971 Published on July 17, 2026

This PowerVM Novalink update is being released to address
IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-14971 can be exploited with local system access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be low. considered to have a small impact on confidentiality and integrity and availability.

Attack Vector:
LOCAL
Attack Complexity:
HIGH
Privileges Required:
HIGH
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
LOW

Weakness Type

Configuration

Weaknesses in this category are typically introduced during the configuration of the software.


Products Associated with CVE-2026-14971

Want to know whenever a new CVE is published for IBM Powervm Novalink? stack.watch will email you.

 

Affected Versions

IBM PowerVM Novalink: