CVE-2023-26286: IBM AIX privilege escalation
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands. IBM X-Force ID: 248421.
Other sources
IBM AIX could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26286?
CVE-2023-26286 is a vulnerability in IBM AIX and VIOS that allows a non-privileged local user to execute arbitrary commands.
Which versions of IBM AIX and VIOS are affected by CVE-2023-26286?
IBM AIX versions 7.1, 7.2, and 7.3, as well as VIOS version 3.1, are affected by CVE-2023-26286.
What is the severity of CVE-2023-26286?
CVE-2023-26286 is classified as high severity with a CVSS score of 8.4.
How can a non-privileged local user exploit the vulnerability in CVE-2023-26286?
A non-privileged local user can exploit the vulnerability in CVE-2023-26286 by exploiting a vulnerability in the AIX runtime services library to execute arbitrary commands.
Is there any additional documentation available for CVE-2023-26286?
Yes, you can find additional documentation for CVE-2023-26286 on the IBM support page and IBM X-Force ID: 248421.