Junglewise Threat Intelligence

CVE-2026-16922: IBM AIX and PowerVM VIOS time-of-check-time-of-use privilege escalation

CVE-2026-16922 · Severity: high · CVSS 7 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS are enterprise Unix operating systems used to run critical business applications. A time-of-check-time-of-use (TOCTOU) race condition allows a local attacker to execute arbitrary code with elevated privileges, potentially compromising the entire system and any applications running on it.

Technical details

A TOCTOU race condition exists in IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1, allowing a local attacker to execute arbitrary code. The vulnerability stems from a gap between a security check and its corresponding use, where an attacker can modify system state between these two operations. Exploitation requires local access and no authentication bypass; the attacker leverages timing manipulation to win a race condition and achieve arbitrary code execution at an elevated privilege level. IBM has released security patches through Service Packs and Fix Packs to remediate this and other vulnerabilities in these releases.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats