Description
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.
Published: 2026-08-12
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows attackers to execute arbitrary code on a Windows machine running IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13. It is caused by a configuration file that is publicly writable when the software is installed for all users, enabling the insertion of malicious configuration directives that are processed by the ACS process. This flaw is a code injection weakness (CWE‑94).

Affected Systems

IBM i Access Client Solutions versions 1.1.2.0 up to 1.1.9.13 deployed on Windows, when installed for all users.

Risk and Exploitability

The CVSS score of 7.8 signals a high‑severity flaw that could allow attackers to gain system‑level privileges. The EPSS score is not available, but the presence of a publicly writable configuration file indicates that local or privileged users could exploit the vulnerability. The issue is not listed in the CISA KEV catalog; however, environments where ACS is installed system‑wide should treat this as a serious risk and apply the fix promptly. Based on the description, the likely attack vector is an attacker with write access to the configuration file, either locally or through compromised credentials.

Generated by OpenCVE AI on August 13, 2026 at 02:53 UTC.

Remediation

Vendor Solution

The issues can be fixed by upgrading to version 1.1.9.14 or later.   See https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11046 7.5SJ11044 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11044 7.4SJ11045 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11045 7.3SJ11043 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11043


OpenCVE Recommended Actions

  • Upgrade IBM i Access Client Solutions to version 1.1.9.14 or later as the vendor provides a fix that removes the writable configuration file issue.
  • If an upgrade cannot be applied immediately, change the installation to user‑only mode or remove write permissions from the configuration file to block unauthorized modifications.
  • Ensure the IBM i Access Client Solutions installation is isolated to the intended user accounts and apply strict file‑permission controls to all configuration files.

Generated by OpenCVE AI on August 13, 2026 at 02:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:i_access_client_solutions:*:*:*:*:*:*:*:*

Fri, 14 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.
Title IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
First Time appeared Ibm
Ibm i Access Client Solutions
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:i_access_client_solutions:1.1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i_access_client_solutions:1.1.9.13:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i Access Client Solutions
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm I Access Client Solutions
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T22:13:33.197Z

Reserved: 2026-06-23T19:07:22.645Z

Link: CVE-2026-13094

cve-icon Vulnrichment

Updated: 2026-08-14T22:13:27.999Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T21:17:34.900

Modified: 2026-08-18T14:58:22.217

Link: CVE-2026-13094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T03:00:09Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')