Executive brief
IBM AIX and PowerVM VIOS are enterprise operating systems and virtualization platforms used to manage critical business infrastructure. A remote attacker can bypass authentication through improper credential handling, potentially allowing unauthorized access and arbitrary command execution on systems running these operating systems.
Technical details
CVE-2026-17142 represents a critical authentication bypass vulnerability in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1. The vulnerability stems from improper authentication handling that allows remote attackers to execute arbitrary commands without valid credentials. The attack is network-accessible with no authentication or user interaction required, as indicated by the 9.8 CVSS score and network attack vector. Security patches have been announced and are available through IBM service packs and fix packs.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed