← Browse

CVE-2026-14971

Low

No strong exploitation signal.

CVSS base
3.9 LOW
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
EPSS — probability of exploitation (30 days)
0.1%
1.0th percentile
CISA KEV
Not listed
Weakness / dates
CWE-16
Published 2026-07-17 · modified 2026-08-11

CVSS breakdown

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

Attack VectorLLocal
Attack ComplexityHHigh
Privileges RequiredHHigh
User InteractionNNone
ScopeUUnchanged
ConfidentialityLLow
IntegrityLLow
AvailabilityLLow

Timeline

Description

IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions.

Affected

ibm

References

Official: NVD · CVE.org