Executive brief
IBM AIX and PowerVM VIOS operating systems contain a vulnerability allowing remote attackers to bypass security restrictions through improper pathname validation. An attacker could exploit this to access restricted directories or execute unauthorized operations, potentially compromising system integrity and data security.
Technical details
CVE-2026-17424 is a pathname validation vulnerability in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1 that allows remote attackers to bypass security restrictions due to improper limitation of pathname access to restricted directories. The vulnerability can be exploited over the network without authentication. An attacker can exploit this flaw to circumvent directory access controls and potentially gain unauthorized access to sensitive files or operations. Patches are available through IBM service packs and fix packs for supported releases.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed
- 2026-08-21: advisory: IBM security bulletin updated with installation instructions