Junglewise Threat Intelligence

CVE-2026-17171: IBM AIX and PowerVM VIOS arbitrary file overwrite via symlink following

CVE-2026-17171 · Severity: high · CVSS 7.8 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 contain a flaw in how they resolve symbolic links, allowing a local attacker to overwrite arbitrary files on the system. This could enable an attacker with local access to modify critical system files, potentially leading to privilege escalation, system compromise, or service disruption.

Technical details

The vulnerability stems from improper resolution of symbolic links in IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1. A local attacker can exploit this flaw to bypass file path validation and overwrite arbitrary files on the system. The attack requires local access to the affected system and involves crafting symlinks to redirect file write operations to unintended targets. Successful exploitation could result in modification of sensitive system files, configuration files, or application binaries, leading to privilege escalation or system compromise. Security updates addressing this vulnerability have been provided by IBM through service packs and fix packs.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed: CVE-2026-17171 published

References

Related threats