SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18848

HIGH · CVSS 8.3 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the ASMI web interface in multiple versions of IBM Power Systems Firmware, allowing an attacker to exploit a crafted web page to perform unauthorized administrative actions on the FSP while the administrator is logged in. This could lead to significant impacts on the confidentiality, integrity, and availability of the managed system. Organizations using the affected firmware should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-18848
Severity
HIGH
CVSS
8.3
EPSS
0.10%

Original NVD Description

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visit a crafted web page can, under specific conditions, silently perform administrative actions on the FSP on behalf of that administrator, resulting in a confidentiality, integrity, and availability impact to the managed system.

Related CVEs

Other vulnerabilities affecting the same vendor(s)