Junglewise Threat Intelligence

CVE-2026-16972: IBM AIX and PowerVM VIOS improper authentication information disclosure

CVE-2026-16972 · Severity: medium · CVSS 6.5 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 are operating systems and virtualization platforms used to run mission-critical enterprise applications. A remote attacker can obtain sensitive information by exploiting improper authentication mechanisms, potentially exposing confidential data without requiring legitimate credentials or access.

Technical details

The vulnerability stems from improper authentication in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1, allowing remote attackers to bypass authentication controls and access sensitive information. The flaw is reachable over the network without requiring prior authentication or user interaction. An attacker can exploit this to obtain confidential data from affected systems. IBM has released security updates through Service Packs and Fix Packs to remediate this vulnerability in supported releases.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed

References

Related threats