CVE-2026-12943 PUBLISHED

This Power Hardware Management Console update is being released to address

Assigner: ibm
Reserved: 22.06.2026 Published: 30.07.2026 Updated: 31.07.2026

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor IBM
Product HMC V10.3.1050.0
Versions
  • affected from 10.3.1050.0 to 10.3.1064.0 (incl.)
Vendor IBM
Product HMC V11.1.1110.0
Versions
  • affected from 11.1.1110.0 to 11.1.1112.0 (incl.)

Solutions

IBM strongly recommends addressing the vulnerability now. The following fixes are available on IBM Fix Central at:

V10R3

https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~9100HMCppc&release=V10R3&platform=All

https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~vHMC&release=V10R3&platform=All

V11R1

https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~9100HMCppc&release=V11R1&platform=All

https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~vHMC&release=V11R1&platform=All

Product

Affected Version(s)

VRMF

APAR

Remediation/Fix

Power HMC

V10.3.1050.0 - V10.3.1064.0

V10.3.1064.1 x86

MB04527

MF71762

Power HMC

V10.3.1050.0 - V10.3.1064.0

V10.3.1064.1 ppc

MB04528

MF71763

Power HMC

V11.1.1110.0 - V11.1.1112.0

V11.1.1112.1 x86

MB04529

MF71764 

Power HMC

V11.1.1110.0 - V11.1.1112.0

V11.1.1112.1 ppc

MB04530

MF71765

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE