Junglewise Threat Intelligence

CVE-2026-18835: IBM AIX and PowerVM VIOS command injection vulnerability

CVE-2026-18835 · Severity: critical · CVSS 9.9 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX 7.2 and 7.3, and IBM PowerVM VIOS 4.1 contain a command injection flaw in the NIM (Network Installation Manager) component that allows authenticated remote attackers to execute arbitrary operating system commands. An attacker with valid credentials could exploit this to gain unauthorized system access, modify files, or launch further attacks within the affected infrastructure.

Technical details

The vulnerability is an improper neutralization of special elements used in an OS command (CWE-78 command injection) within IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1. The flaw exists in the Network Installation Manager (NIM) component, which fails to properly sanitize user-supplied input before passing it to OS command execution routines. An authenticated remote attacker can exploit this by crafting malicious input containing shell metacharacters to break out of the intended command context and execute arbitrary commands with the privileges of the NIM process. The vulnerability requires valid authentication credentials but operates over the network. Security patches delivered via Service Packs (SPs) and Fix Packs (FPs) are available from IBM.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed: Vulnerability disclosed by IBM

References

Related threats