Local Privilege Escalation in IBM AIX and PowerVM Products
CVE-2026-16927
7.3HIGH
What is CVE-2026-16927?
A vulnerability in IBM AIX versions 7.2 and 7.3, along with IBM PowerVM VIOS 4.1, may allow a local attacker to exploit a time-of-check to time-of-use (TOCTOU) race condition. This flaw could enable unauthorized elevation of privileges, granting the attacker root access to the system. Operators of these products should assess their environments and implement the necessary patches to safeguard against potential exploits.
Affected Version(s)
AIX 7.2
AIX 7.3
PowerVM VIOS 4.1
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
CVE-2026-14970, CVE-2026-15061, CVE-2026-15078, CVE-2026-15065, CVE-2026-15068 were reported to IBM by Oneconsult AG (https://oneconsult.com/).