Description
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.
Published: 2026-08-12
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to exploit the Zip Slip path traversal flaw that occurs when importing a configuration file into IBM i Access Client Solutions. By crafting a malicious archive, the attacker can cause the application to write files outside the intended directory, potentially overwriting critical system files or dropped payloads. This arbitrary file write can lead to local or remote code execution depending on the privileges of the user performing the import.

Affected Systems

Affected are IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13. The vulnerability applies to all instances of the product listed by IBM as i Access Client Solutions.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. Although EPSS is not available, the lack of availability and the nature of the flaw suggest a realistic exploitation possibility, especially in environments where configuration import is enabled for untrusted users. The vulnerability is not listed in the CISA KEV catalog, but its high CVSS and potential for remote code execution make it a priority for remediation.

Generated by OpenCVE AI on August 13, 2026 at 02:32 UTC.

Remediation

Vendor Solution

The issues can be fixed by upgrading to version 1.1.9.14 or later.   See https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11046 7.5SJ11044 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11044 7.4SJ11045 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11045 7.3SJ11043 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11043


OpenCVE Recommended Actions

  • Upgrade IBM i Access Client Solutions to version 1.1.9.14 or later.
  • Restrict the configuration import functionality to trusted administrators only.
  • Verify that no unexpected files are written during configuration imports and review system logs for anomalous activity.

Generated by OpenCVE AI on August 13, 2026 at 02:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:i_access_client_solutions:*:*:*:*:*:*:*:*

Thu, 13 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.
Title IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
First Time appeared Ibm
Ibm i Access Client Solutions
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:i_access_client_solutions:1.1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i_access_client_solutions:1.1.9.13:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i Access Client Solutions
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm I Access Client Solutions
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T12:57:29.394Z

Reserved: 2026-06-23T19:42:55.906Z

Link: CVE-2026-13105

cve-icon Vulnrichment

Updated: 2026-08-13T12:56:23.283Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T21:17:35.027

Modified: 2026-08-18T14:53:24.063

Link: CVE-2026-13105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:45:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')