CVE-2026-19492
Last modified
CVE-2026-19492 is a low-severity vulnerability rated 3.2/10 on the CVSS scale. IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging to the hypervisor or other guest partitions hosted on the same system, resulting in a confidentiality impact.
Description
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a limited amount of hypervisor memory, potentially exposing sensitive data belonging to the hypervisor or other guest partitions hosted on the same system, resulting in a confidentiality impact. The attacker has no control over which memory contents are returned. This vulnerability is of particular concern in multi-tenant environments where guests may run arbitrary OS images.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| IBM | PowerVM Hypervisor | >= FW1120.00, <= FW1120.01; >= FW1110.00, <= FW1110.31; >= FW1060.00, <= FW1060.81 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-19492?
How severe is CVE-2026-19492?
How do I fix CVE-2026-19492?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19485A Predictable Resource Name vulnerability in BigQuery Import…9.3
- CVE-2026-19486A Server-Side Request Forgery (SSRF) vulnerability in Google…8.7
- CVE-2026-19487Perl versions from 5.9.4 before 5.41.9 produce incorrect reg…5.3
- CVE-2026-19489Vulnerability in NetScaler ADC and NetScaler Gateway. This …8.8
- CVE-2026-1949Delta Electronics AS320T has incorrect calculation of the bu…9.8
- CVE-2026-19490Vulnerability in NetScaler ADC and NetScaler Gateway. This …9.8
- CVE-2026-19499Calling strfmon and strfmon_l in the GNU C Library version 2…7.7
- CVE-2026-1950Delta Electronics AS320T has No checking of the length of t…9.8
- CVE-2026-19500The Entries component in Brainstorm Force SureForms version,…7.5
- CVE-2026-19501CSV export functionality in Brainstorm Force SureForms versi…8.8
- CVE-2026-19502MongoDB SQL Schema Builder CLI records its startup configura…5.5
- CVE-2026-19503MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do …4.8
Are you affected by CVE-2026-19492?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
