CVE-2026-18824: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AIX 7.3 TL04to a version that resolves this vulnerability.Fixed in SP2 - Upgrade
Upgrade
AIX 7.3 TL03to a version that resolves this vulnerability.Fixed in SP3 - Upgrade
Upgrade
AIX 7.3 TL02to a version that resolves this vulnerability.Fixed in SP5 - Upgrade
Upgrade
AIX 7.2 TL05to a version that resolves this vulnerability.Fixed in SP13 - Upgrade
Upgrade
PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508 - Upgrade
Upgrade
PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408 - Upgrade
Upgrade
PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308 - Compensating control
If applying these patches using nimsh secure, take the special steps noted in the IBM instructions because the protocol between master and client is updated to be more secure.
- Operational
Reboot the LPAR after applying the AIX Service Pack (SP) / VIOS Fix Pack (FP) update to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, perform additional steps required to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
- Operational
On AIX, Live Update can be used to avoid a reboot.
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must be remote and authenticated. The available information does not indicate that unauthenticated attackers can exploit it.
What is the potential impact of successful exploitation?
A successful attacker could execute arbitrary commands on the affected system.
Which products should be assessed for exposure?
Assess IBM AIX systems and IBM PowerVM VIOS systems for this vulnerability.