Junglewise Threat Intelligence

CVE-2026-16927: IBM AIX and PowerVM VIOS privilege escalation via race condition

CVE-2026-16927 · Severity: high · CVSS 7.3 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS are operating systems and virtualization platforms used to run mission-critical enterprise applications. A local attacker can exploit a time-of-check to time-of-use (TOCTOU) race condition to gain root privileges, potentially compromising the entire system and all hosted applications.

Technical details

The vulnerability is a time-of-check to time-of-use (TOCTOU) race condition in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 that allows a local attacker to escalate privileges to root. TOCTOU vulnerabilities occur when a check is performed on a resource (such as file permissions), but the resource can be modified between the check and the actual use, allowing an attacker to bypass security controls. This vulnerability requires local access to the system. An attacker with local user access can exploit this race condition to gain root privileges and assume full control of the operating system. IBM has provided security updates through Service Packs and Fix Packs to remediate this vulnerability.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats