Junglewise Threat Intelligence

CVE-2026-16932: IBM AIX and PowerVM VIOS privilege escalation via ODMDIR environment variable

CVE-2026-16932 · Severity: high · CVSS 8.8 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 fail to properly validate the ODMDIR environment variable, allowing a local user to execute arbitrary commands with elevated privileges. An attacker with local access can exploit this to bypass security controls and run malicious code on affected systems, potentially compromising the entire operating environment.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats