CVE-2026-16821
largeFormat string local privilege escalation in IBM AIX 7.2/7.3 and PowerVM VIOS 4.1
CVE-2026-16821 is a format string vulnerability (CWE-134) in IBM AIX 7.2, AIX 7.3, and IBM PowerVM VIOS 4.1 that could allow a local attacker to gain elevated privileges. The flaw is triggered when a locally authenticated, low-privileged user causes attacker-controlled format directives to reach a formatting function, corrupting process memory on the affected system. Successful exploitation has high impact on confidentiality, integrity, and availability per the CVSS vector, which for a local privilege escalation on AIX/VIOS effectively means root-level compromise of the LPAR or Virtual I/O Server. Only customers running the stated releases, AIX 7.2, AIX 7.3, or PowerVM VIOS 4.1, are in scope; other releases are not listed as affected. There is currently no evidence of exploitation: the flaw is not in CISA KEV, EPSS is about 0.1% (1st percentile), and no public proof-of-concept is known.
What to do: Monitor IBM PSIRT for the security bulletin tied to CVE-2026-16821 and apply the interim fix or service update for AIX 7.2, AIX 7.3, and VIOS 4.1 as soon as it is published, confirming current fileset levels with lslpp before and after patching. Until systems are patched, restrict local logins on affected LPARs and Virtual I/O Servers to trusted users, since exploitation requires only a local low-privilege account and no user interaction.
| IBM AIX | 7.2, 7.3 |
| IBM PowerVM VIOS | 4.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.
- Vendors
- ibm
- Products
- aix, vios
- Weakness
- CWE-134
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.