SB2026100935 - Multiple vulnerabilities in IBM PowerVC



SB2026100935 - Multiple vulnerabilities in IBM PowerVC

Published: October 9, 2026

Security Bulletin ID SB2026100935
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Input validation error (CVE-ID: CVE-2026-53666)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger unexpected constructor execution on the client.

The vulnerability exists due to improper input validation in the SSR hydration process when processing attacker-supplied input that overwrites certain aspects of errors caught by SSR. A remote attacker can supply crafted input to trigger unexpected constructor execution on the client.

This only affects Framework Mode and Data Mode applications performing manual SSR and hydration, and does not impact Declarative Mode.


2) Open redirect (CVE-ID: CVE-2026-53669)

CWE-ID: CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to redirect users to an external site.

The vulnerability exists due to open redirect in navigation mechanisms when processing attacker-supplied paths. A remote attacker can supply a crafted path to trigger an unexpected external navigation to redirect users to an external site.


3) Input validation error (CVE-ID: CVE-2025-68470)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to redirect the application to an external URL.

The vulnerability exists due to improper input validation in navigation path handling when processing attacker-supplied paths passed to navigate(), Link, or redirect(). A remote user can supply a crafted path to redirect the application to an external URL.

This issue only occurs when untrusted content is passed into navigation paths in application code.


Remediation

Install update from vendor's website.