CVE-2026-16991
published 2026-08-20CVE-2026-16991: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper handling of symbolic links.
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.10%
0.9th percentile
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper handling of symbolic links.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | 7.2.5 – 7.2.5.212 | — |
| ibm | aix | 7.3.2 – 7.3.2.5 | — |
| ibm | aix | 7.3.3 – 7.3.3.2 | — |
| ibm | aix | 7.3.4 – 7.3.4.1 | — |
| ibm | powervm_vios | — | — |
| ibm | vios | >= 4.1.0 < 4.1.0.50 | 4.1.0.50 |
| ibm | vios | >= 4.1.1.0 < 4.1.1.30 | 4.1.1.30 |
| ibm | vios | >= 4.1.2.0 < 4.1.2.20 | 4.1.2.20 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper handling of symbolic links.
ghsa_unreviewed·2026-08-21
CVE-2026-16991 [HIGH] CWE-269 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper handling of symbolic links.
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper handling of symbolic links.
VulDB
IBM AIX/PowerVM VIOS privileges management
vuldb·2026-08-21·CVSS 7.8
CVE-2026-16991 [HIGH] IBM AIX/PowerVM VIOS privileges management
A vulnerability, which was classified as very critical, has been found in IBM AIX and PowerVM VIOS. The impacted element is an unknown function. This manipulation causes improper privilege management.
This vulnerability is handled as CVE-2026-16991. It is possible to launch the attack on the local host. There is not any exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-20
Published