Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-17429

CVE-2026-17429: IBM Power Systems Privilege Escalation

CVE-2026-17429 is a privilege escalation vulnerability in IBM Power Systems Firmware that allows attackers with BMC/FSP access to gain full control over host systems. This article covers technical details, affected versions, and mitigation.

Updated:

CVE-2026-17429 Overview

CVE-2026-17429 affects IBM Power Systems Firmware across multiple release trains, including FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC). The flaw resides in the interface between the Baseboard Management Controller/Flexible Service Processor (BMC/FSP) and the host system. An attacker with service account or root access to the BMC/FSP can write arbitrary data to hardware control registers. This exposure maps to [CWE-863: Incorrect Authorization] and impacts confidentiality, integrity, and availability of the host and all hosted partitions.

Critical Impact

Arbitrary writes to hardware control registers from the BMC/FSP grant full control over the host system and every hosted logical partition (LPAR).

Affected Products

  • IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80
  • IBM Power Systems Firmware FW950.00 through FW950.H2
  • IBM Power9 firmware OP940.00 through OP940.a1 and Power HMC firmware OP940.00 through OP940.81

Discovery Timeline

  • 2026-08-19 - CVE-2026-17429 published to NVD
  • 2026-08-20 - Last updated in NVD database

Technical Details for CVE-2026-17429

Vulnerability Analysis

The vulnerability sits at the trust boundary between the BMC/FSP and the host processor complex. The BMC/FSP performs privileged platform management functions, including power sequencing, thermal control, and low-level hardware initialization. On affected IBM Power Systems firmware, the interface exposed to service-level actors does not properly restrict which hardware control registers can be written. An attacker with service account or root access on the BMC/FSP can therefore issue arbitrary register writes into the host domain. This crosses a security boundary between the management processor and the host, which is why the scope changes in the CVSS assessment.

Root Cause

The root cause is an authorization gap [CWE-863] in the BMC/FSP-to-host interface. The firmware allows a privileged service-side principal to reach hardware control registers that should be gated by stricter policy. As a result, service-level administrative access effectively becomes host-level control.

Attack Vector

Exploitation requires the attacker to already hold service account or root privileges on the BMC/FSP. From that position, the attacker writes arbitrary values to hardware control registers reachable through the management interface. Successful writes yield full control of the host, including all logical partitions running on the system, enabling data theft, tampering with partition state, and denial of service across the platform.

No verified public exploit code is available for this issue. Refer to the IBM Support Page for vendor technical details.

Detection Methods for CVE-2026-17429

Indicators of Compromise

  • Unexpected BMC/FSP service account logins, new local accounts, or SSH key additions on the management processor.
  • Unscheduled writes to hardware control registers, unexplained partition resets, or host checkstops recorded in service processor logs.
  • Firmware update, dump, or diagnostic operations initiated outside approved change windows.

Detection Strategies

  • Forward BMC/FSP and HMC audit logs to a central platform and alert on privileged command execution, register-level operations, and configuration changes.
  • Baseline expected service-processor administrative activity and flag deviations, particularly interactive root sessions and out-of-band tooling.
  • Correlate host-side anomalies such as partition crashes or PowerVM hypervisor errors with management-plane activity occurring in the same window.

Monitoring Recommendations

  • Restrict and monitor network paths to BMC/FSP and HMC management interfaces, treating them as tier-0 assets.
  • Track firmware version inventory for FW1120, FW1110, FW1060, FW950, and OP940 branches to identify systems still exposed to CVE-2026-17429.
  • Review authentication events for all service accounts on management processors and alert on credential reuse across systems.

How to Mitigate CVE-2026-17429

Immediate Actions Required

  • Apply the fixed firmware levels published on the IBM Support Page for each affected FW1120, FW1110, FW1060, FW950, and OP940 train.
  • Rotate all BMC/FSP and HMC service and root credentials, and remove any unused local accounts or SSH keys.
  • Confirm management interfaces are isolated on a dedicated administrative network segment, not routable from user or workload VLANs.

Patch Information

IBM has published remediation guidance for CVE-2026-17429 on the IBM Support Page. Administrators should identify the affected firmware branch on each managed system and upgrade to the vendor-designated fixed level. Because the issue affects the interface between the BMC/FSP and the host, firmware updates must be applied to the service processor components, not just to host operating systems or partitions.

Workarounds

  • Limit BMC/FSP and HMC access to a small set of named administrators and require multi-factor authentication on any jump host used for management access.
  • Disable unused management protocols and services on the BMC/FSP and enforce strong password policies for all service accounts.
  • Enable full audit logging on service processors and HMC, retain logs off-box, and review privileged session activity on a regular cadence until patched.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.