Executive brief
IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 Network Installation Manager (NIM) stores sensitive certificate authority private keys in publicly accessible update files. An attacker with network access can obtain these keys to bypass security restrictions and impersonate trusted entities, potentially gaining unauthorized access to systems and data.
Technical details
The vulnerability (CVE-2026-15065) exists in IBM AIX and PowerVM VIOS NIM due to cleartext storage of intermediate certificate authority private keys in publicly available update files. This is a CWE-312 vulnerability where sensitive cryptographic material is exposed without proper access controls. No authentication or special privileges are required to download the affected update files from the network. An attacker can extract the private keys and use them to conduct man-in-the-middle attacks, forge certificates, or bypass security mechanisms that rely on certificate validation. IBM has released security patches through Service Packs (SPs) and Fix Packs (FPs) for affected supported releases.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed: Vulnerability disclosed in security bulletin
- 2026-08-21: advisory: IBM security bulletin updated with installation instructions