CVE-2026-16703: Vulnerabilities in IBM AIX and PowerVM VIOS
AIX could allow a local attacker to gain elevated privileges due to improper privilege management.
Other sources
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AIX 7.2 TL05 SP13to a version that resolves this vulnerability.Patch SPKEY7.2.5 - Upgrade
Upgrade
AIX 7.3 TL04 SP2to a version that resolves this vulnerability.Patch IJ5956608/14/2026 - Upgrade
Upgrade
AIX 7.3 TL03 SP3to a version that resolves this vulnerability.Patch IJ5956508/14/2026 - Upgrade
Upgrade
AIX 7.3 TL02 SP5to a version that resolves this vulnerability.Patch IJ5956408/14/2026 - Upgrade
Upgrade
AIX 7.2 TL05 SP13 (SPKEY7.2.5) cumulative remediationto a version that resolves this vulnerability.Patch IJ59563 - Upgrade
Upgrade
PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch key_w_apar - Upgrade
Upgrade
PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar - Upgrade
Upgrade
PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar - Configuration
On AIX, use Live Update to avoid rebooting where applicable.
AIX Live Update reboot_avoidance = use Live Update to avoid a reboot - Operational
Perform an LPAR reboot to complete the SP/FP update after applying the AIX Service Pack / VIOS Fix Pack remediation levels.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, complete the additional steps required to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
Event History
Frequently Asked Questions
Which systems are in scope for this issue?
The issue affects IBM AIX and IBM PowerVM VIOS.
What level of access would an attacker need?
Exploitation requires local access to the affected system. A successful attacker could gain elevated privileges.