IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Format String V local PrivEsc
CVE-2026-16821 Published on August 28, 2026
Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.
Vulnerability Analysis
CVE-2026-16821 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Use of Externally-Controlled Format String
The software uses a function that accepts a format string as an argument, but the format string originates from an external source.
Products Associated with CVE-2026-16821
stack.watch emails you whenever new vulnerabilities are published in IBM Aix or IBM Powervm Vios. Just hit a watch button to start following.
Affected Versions
IBM AIX:- Version 7.2 is affected.
- Version 7.3 is affected.
- Version 4.1 is affected.