Executive brief
IBM AIX and PowerVM VIOS are enterprise operating systems used to run critical business applications and virtualization infrastructure. A remote authenticated attacker can exploit improper handling of special characters in OS commands to execute arbitrary code with system privileges, potentially compromising entire server environments and the applications they host.
Technical details
The vulnerability is an OS command injection flaw (CWE-78 class, improper neutralization of special elements in OS commands) in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1. It requires authentication to exploit but allows a remote attacker to execute arbitrary commands on the affected system. The NIM (Network Installation Management) component appears to be the affected vector. Successful exploitation grants the attacker command execution at the privilege level of the vulnerable process, potentially leading to full system compromise. IBM has released security updates through Service Packs and Fix Packs.
Affected products
- IBM AIX 7.2, 7.3
- IBM PowerVM VIOS 4.1
Timeline
- 2026-08-20: disclosed: Published on NVD
- 2026-08-21: advisory: IBM security bulletin updated with installation instructions