Vulnerability Details CVE-2026-14971
IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 0.9%
CVSS Severity
CVSS v3 Score 3.9
Products affected by CVE-2026-14971
-
cpe:2.3:a:ibm:powervm_novalink:2.2.0
-
cpe:2.3:a:ibm:powervm_novalink:2.2.1.1
-
cpe:2.3:a:ibm:powervm_novalink:2.3.0
-
cpe:2.3:a:ibm:powervm_novalink:2.3.1