CVE-2026-12943 Details
Description
IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
A command injection vulnerability has been identified in IBM Power Hardware Management Console (HMC) versions 10.3.1050.0 through 10.3.1064.0 and 11.1.1110.0 through 11.1.1112.0. This vulnerability could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system. The issue arises from improper validation of user-supplied input.
Users are advised to upgrade to HMC version 10.3.1064.1 or 11.1.1112.1, depending on their current version. These updates are available through IBM Fix Central.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7278667 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm hardware management console | >= 10.3.1050.0, < 10.3.1064.1 >= 11.1.1110.0, < 11.1.1112.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | Initial Analysis | [email protected] |
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |
| Jul 30, 2026 | CVE Modified | CISA-ADP |