Junglewise Threat Intelligence

CVE-2026-16925: IBM AIX and PowerVM VIOS privilege escalation due to improper authorization

CVE-2026-16925 · Severity: high · CVSS 7.1 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS are operating system and virtualization platforms used to run critical business applications. A local attacker with limited system access could exploit an authorization flaw to gain elevated administrative privileges, potentially compromising the entire system and all applications running on it.

Technical details

The vulnerability stems from improper authorization checks in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1. A local attacker can exploit this flaw to achieve privilege escalation. The vulnerability is reachable only via local access (not remotely exploitable). IBM has released security patches through Service Packs and Fix Packs for supported releases under active fix support, and customers are advised to apply these updates promptly.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM security bulletin updated with additional installation instructions

References

Related threats