CVE-2026-16923: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch key_w_apar4.1.1IJ5956408/14/2026 - Upgrade
Upgrade
IBM PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch key_w_apar4.1.2IJ5956308/14/2026 - Operational
Reboot the LPAR to complete the SP/FP update (AIX Level and VIOS Fix Pack/APAR updates require an LPAR reboot to complete the update).
- Operational
If running VIOS 4.1.0 or VIOS 4.1.1: after applying the 4.1.0.50 or 4.1.1.30 FPs, complete the additional steps to migrate to the latest Postgres15 (post-update steps required after these VIOS FP levels).
- Operational
If applying AIX/VIOS patches using nimsh secure: use the special nimsh secure steps because the master-client protocol is updated to be more secure.
Event History
Frequently Asked Questions
Is direct remote exploitation indicated?
No. The available information describes exploitation by a local attacker, so an attacker would need local access to an affected IBM AIX or IBM PowerVM VIOS system.
Which environments should be prioritized for review?
Prioritize IBM AIX and IBM PowerVM VIOS systems that permit local access by users who should not be able to obtain elevated privileges. No affected versions or configuration conditions are provided.