Executive brief
IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 contain a flaw in how they handle symbolic links, allowing a local user with basic access to gain elevated system privileges. This could enable an attacker to bypass security restrictions, modify critical system files, or gain full control of the operating system.
Technical details
CVE-2026-16991 is a symlink-following vulnerability (CWE-61) in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1. The vulnerability stems from improper handling of symbolic links during file operations, likely in system utilities or privileged processes. A local attacker (requiring existing user-level access) can exploit this by creating malicious symlinks to redirect privileged file operations to arbitrary locations, achieving privilege escalation. The attack vector is local and requires no network access or special privileges beyond basic user-level access. IBM has released security updates through Service Packs (SPs) and Fix Packs (FPs) to remediate this issue.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed