CVE-2026-19449: Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AIX 7.2 TL05 SP13to a version that resolves this vulnerability.Fixed in SP13Patch IJ5956608 - Upgrade
Upgrade
AIX 7.3 TL04 SP2to a version that resolves this vulnerability.Fixed in SP2Patch IJ5956508 - Upgrade
Upgrade
AIX 7.3 TL03 SP3to a version that resolves this vulnerability.Fixed in SP3Patch IJ5956408 - Upgrade
Upgrade
AIX 7.3 TL02 SP5to a version that resolves this vulnerability.Fixed in SP5Patch IJ59563 - Upgrade
Upgrade
PowerVM VIOS 4.1.0to a version that resolves this vulnerability.Fixed in 4.1.0.50Patch IJ5956508 - Upgrade
Upgrade
PowerVM VIOS 4.1.1to a version that resolves this vulnerability.Fixed in 4.1.1.30Patch IJ5956408 - Upgrade
Upgrade
PowerVM VIOS 4.1.2to a version that resolves this vulnerability.Fixed in 4.1.2.20Patch IJ5956308 - Operational
Reboot the LPAR after applying the AIX Service Pack (SP)/VIOS Fix Pack (FP) update to complete the SP/FP update.
- Operational
For VIOS 4.1.0 and VIOS 4.1.1, complete the additional post-update steps required to migrate to the latest Postgres15 after applying the 4.1.0.50 or 4.1.1.30 FPs.
Event History
Frequently Asked Questions
Who can exploit this issue?
An unprivileged local user may be able to exploit the vulnerability. The provided information does not indicate that it is remotely exploitable.
What level of access could exploitation provide?
Successful exploitation may cause an attacker-controlled payload to execute as root, resulting in root-level privileges.
Which products should be assessed?
Assess IBM AIX systems and IBM PowerVM VIOS systems, as both are listed as affected software.