IBM disclosed a CVSS 9.8 improper authentication flaw that, per the vendor's advisory, could allow an unauthenticated remote attacker to gain root privileges on IBM AIX 7.2/7.3 and PowerVM VIOS 4.1.
What Is It
CVE-2026-16656 is an improper authentication vulnerability (CWE-287) in IBM AIX and IBM PowerVM VIOS. Per IBM's advisory, the flaw "could allow a remote attacker to gain root privileges due to improper authentication."
IBM PSIRT assigned a CVSS 3.1 base score of 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Every exploitability parameter is at its worst setting: network-reachable, low attack complexity, no privileges required, and no user interaction. Impact is scored as total; high confidentiality, integrity, and availability loss, consistent with the root-level compromise IBM describes.
The record was published on 2026-08-19 with a status of "Received," meaning NVD enrichment analysis is still pending. IBM's advisory does not describe the vulnerable component, the attack vector in technical detail, or any preconditions beyond network reachability.
Why It Matters
If the flaw behaves as the CVSS metrics describe, an unauthenticated network attacker reaching root would be the highest-severity outcome in the AIX/VIOS stack. On PowerVM VIOS specifically, the Virtual I/O Server sits beneath hosted LPARs, so root there is a privileged position in the virtualization layer, not merely a single-host compromise.
The exploitability sub-score is 3.9, the maximum possible, indicating IBM assessed no meaningful barriers between an attacker with network access and full system control.
As of 2026-08-19, CVE-2026-16656 does not appear in CISA's Known Exploited Vulnerabilities catalog (linked below; readers can verify current status there, as the catalog is updated on a rolling basis). There is likewise no confirmation of active exploitation in the vendor advisory or NVD record, no public proof-of-concept referenced by IBM, and consequently no KEV-mandated remediation deadline for federal agencies.
What's Vulnerable
Confirmed affected products, per IBM PSIRT:
- IBM AIX: 7.2 (including 7.2.0) and 7.3 (including 7.3.0)
- IBM PowerVM VIOS: 4.1 (including 4.1.0)
No other versions or products are listed as affected in IBM's advisory.
Patch Status
IBM has published a security bulletin at support page node 7283858. The advisory data available at publication does not specify fix levels, iFix identifiers, or workarounds; administrators should consult the IBM bulletin directly for applicable APARs and interim fixes for their release.
Given the vendor's 9.8 rating and the absence of any required privileges or user interaction, patching should be treated as urgent regardless of KEV status.
Sources
- NVD, CVE-2026-16656: https://nvd.nist.gov/vuln/detail/CVE-2026-16656
- IBM Security Bulletin ([email protected]): https://www.ibm.com/support/pages/node/7283858
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog