CVE-2026-17145

9.8

IBM · AIX

IBM AIX and PowerVM VIOS contain an improper privilege management vulnerability that enables remote, unauthenticated attackers to execute arbitrary code.

Executive summary

A critical vulnerability in IBM AIX and PowerVM VIOS enables remote, unauthenticated attackers to execute arbitrary code by bypassing privilege management controls.

Vulnerability

The vulnerability is caused by improper privilege management, identified as CWE-269. This defect allows an unauthenticated remote attacker to perform actions with elevated privileges that should be restricted.

Business impact

An attacker successfully exploiting this vulnerability can gain administrative control over the affected system. This level of access enables the theft of sensitive information, the installation of malicious software, and the disruption of critical business processes. The CVSS score of 9.8 reflects the high probability and impact of such an attack.

Remediation

Immediate Action: Deploy the applicable IBM APAR fixes, including IJ59564 for AIX 7.3.3 or IJ59563 for VIOS 4.1.2, to resolve the privilege management deficiency.

Proactive Monitoring: Monitor for unusual privilege escalation events or unauthorized administrative commands within system audit logs.

Compensating Controls: Utilize host-based intrusion detection systems to identify and block attempts to execute unauthorized commands or access restricted system files.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this vulnerability, immediate patching is required to prevent unauthorized access. Organizations should verify that all AIX and VIOS instances are updated to the current recommended service levels to mitigate the risk of remote code execution.

More IBM CVEs