ZeroHour

CVE-2026-16821

large

Format string local privilege escalation in IBM AIX 7.2/7.3 and PowerVM VIOS 4.1

CVSS 3.1
7.8 high
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-16821 is a format string vulnerability (CWE-134) in IBM AIX 7.2, AIX 7.3, and IBM PowerVM VIOS 4.1 that could allow a local attacker to gain elevated privileges. The flaw is triggered when a locally authenticated, low-privileged user causes attacker-controlled format directives to reach a formatting function, corrupting process memory on the affected system. Successful exploitation has high impact on confidentiality, integrity, and availability per the CVSS vector, which for a local privilege escalation on AIX/VIOS effectively means root-level compromise of the LPAR or Virtual I/O Server. Only customers running the stated releases, AIX 7.2, AIX 7.3, or PowerVM VIOS 4.1, are in scope; other releases are not listed as affected. There is currently no evidence of exploitation: the flaw is not in CISA KEV, EPSS is about 0.1% (1st percentile), and no public proof-of-concept is known.

What to do: Monitor IBM PSIRT for the security bulletin tied to CVE-2026-16821 and apply the interim fix or service update for AIX 7.2, AIX 7.3, and VIOS 4.1 as soon as it is published, confirming current fileset levels with lslpp before and after patching. Until systems are patched, restrict local logins on affected LPARs and Virtual I/O Servers to trusted users, since exploitation requires only a local low-privilege account and no user interaction.

Affected
IBM AIX7.2, 7.3
IBM PowerVM VIOS4.1
Estimated exposure
largetens of thousands of enterprise AIX LPARs/PowerVM partitions worldwide (no public scan counts) — AIX 7.x and PowerVM VIOS run on IBM Power Systems almost exclusively in enterprise and government data centers, and deployment patterns suggest an active installed base of AIX 7.2/7.3 and VIOS 4.1 partitions in the tens of thousands,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.

Vendors
ibm
Products
aix, vios
Weakness
CWE-134
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.