Junglewise Threat Intelligence

CVE-2026-19449: IBM AIX and PowerVM VIOS cmdnim privilege escalation

CVE-2026-19449 · Severity: high · CVSS 8.8 · Published 2026-08-20

Technologies: IBM Aix, IBM PowerVM VIOS. Vendors: IBM.

Executive brief

IBM AIX and PowerVM VIOS include a command-line utility (cmdnim) used for system and network management tasks. An unprivileged local user can exploit a vulnerability in this utility to execute arbitrary code with root privileges, potentially gaining complete control of the affected system.

Technical details

A privilege escalation vulnerability exists in the cmdnim utility in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1. An unprivileged local user can exploit this flaw to execute arbitrary payload code with root-level privileges. The attack requires local access but does not require elevated privileges or user interaction. This is a direct privilege escalation vulnerability with immediate practical implications for system compromise. Patches are available through IBM service packs and fix packs.

Affected products

  • IBM AIX 7.2, 7.3
  • IBM PowerVM VIOS 4.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-21: patched: IBM released security updates through service packs and fix packs

References

Related threats