IBM Power Systems Firmware FSP Auth Bypass (FW1120)
CVE-2026-16835 Published on August 19, 2026
Power System Improper Certificate Validation
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system.
Vulnerability Analysis
Weakness Type
Improper Certificate Validation
The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Products Associated with CVE-2026-16835
Want to know whenever a new CVE is published for IBM Power Systems Firmware? stack.watch will email you.
Affected Versions
IBM Power Systems Firmware:- Version FW1120.00 is affected.
- Version FW1110.00, <= FW1110.30 is affected.
- Version FW1060.00, <= FW1060.80 is affected.
- Version FW950.00, <= FW950.H2 is affected.