Remote Pathname Bypass in IBM AIX and PowerVM Products
CVE-2026-17424

4.8MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
20 August 2026

What is CVE-2026-17424?

A vulnerability exists in IBM AIX 7.2, 7.3, and IBM PowerVM VIOS 4.1 that allows remote attackers to bypass security restrictions. This flaw arises from improper handling of pathnames, granting unauthorized access to restricted directories. Attackers could exploit this vulnerability to manipulate files or execute malicious actions on the affected systems, thereby compromising their security integrity. Immediate remediation is advised.

Affected Version(s)

AIX 7.2

AIX 7.3

PowerVM VIOS 4.1

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CVE-2026-14970, CVE-2026-15061, CVE-2026-15078, CVE-2026-15065, CVE-2026-15068 were reported to IBM by Oneconsult AG (https://oneconsult.com/).
.