IBM AIX 7.2/7.3 PowerVM VIOS 4.1: Local Code Exec via Pointer Validation
CVE-2026-18840 Published on August 20, 2026
Vulnerabilities in IBM AIX and PowerVM VIOS
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer.
Vulnerability Analysis
CVE-2026-18840 is exploitable with local system access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Untrusted Pointer Dereference
The program obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
Products Associated with CVE-2026-18840
stack.watch emails you whenever new vulnerabilities are published in IBM Aix or IBM Powervm Vios. Just hit a watch button to start following.
Affected Versions
IBM AIX:- Version 7.2 is affected.
- Version 7.3 is affected.
- Version 4.1 is affected.