Junglewise Threat Intelligence

CVE-2026-16989: IBM AIX and PowerVM VIOS privilege escalation via symlink resolution

CVE-2026-16989 · Severity: high · CVSS 7.1 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain a flaw in how they resolve symbolic links, allowing a local attacker to exploit improper link handling and gain elevated system privileges. A successful attack would grant an attacker root or system-level access to the affected server, potentially enabling full control over critical business infrastructure and data.

Technical details

This vulnerability involves improper resolution of symbolic links in IBM AIX and PowerVM VIOS, a local privilege escalation (CWE-61 / CWE-367 class issue). An attacker with local access to an affected system can craft malicious symbolic links to trick the operating system or its utilities into accessing files with elevated privileges. The attack requires local access (not network-exploitable) and no special authentication beyond having a user account on the system. Successful exploitation grants the attacker elevated privileges, potentially reaching root level. Patches are available through IBM service packs and fix packs for supported AIX and VIOS releases.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: advisory: IBM security bulletin updated

References

Related threats