SB2026100935 - Multiple vulnerabilities in IBM PowerVC
Published: October 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Input validation error (CVE-ID: CVE-2026-53666)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger unexpected constructor execution on the client.
The vulnerability exists due to improper input validation in the SSR hydration process when processing attacker-supplied input that overwrites certain aspects of errors caught by SSR. A remote attacker can supply crafted input to trigger unexpected constructor execution on the client.
This only affects Framework Mode and Data Mode applications performing manual SSR and hydration, and does not impact Declarative Mode.
2) Open redirect (CVE-ID: CVE-2026-53669)
CWE-ID: CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to redirect users to an external site.
The vulnerability exists due to open redirect in navigation mechanisms when processing attacker-supplied paths. A remote attacker can supply a crafted path to trigger an unexpected external navigation to redirect users to an external site.
3) Input validation error (CVE-ID: CVE-2025-68470)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to redirect the application to an external URL.
The vulnerability exists due to improper input validation in navigation path handling when processing attacker-supplied paths passed to navigate(), Link, or redirect(). A remote user can supply a crafted path to redirect the application to an external URL.
This issue only occurs when untrusted content is passed into navigation paths in application code.
Remediation
Install update from vendor's website.