Description
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.
Published: 2026-08-12
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 allow downloading of unverified product code when configured to update from an IBM i system. This flaw permits an attacker to supply malicious code that the client will download and execute, effectively enabling remote code execution on the user’s workstation. The vulnerability is identified as CWE‑494, underscoring the risk of executing untrusted code.

Affected Systems

The affected products are IBM i Access Client Solutions, specifically the 1.1.2.0 to 1.1.9.13 releases. Any installation that uses the automatic update feature and pulls updates from an IBM i environment is at risk unless updated to 1.1.9.14 or later. The CVE covers both the base client and related updater components, and any version between the stated range is susceptible.

Risk and Exploitability

This issue carries a high CVSS score of 8.3, indicating significant severity, though EPSS data is not available and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector appears to be remote through the update mechanism; a malicious actor would need access to the IBM i system providing the update or influence the update source to serve forged code. Successful exploitation would allow arbitrary code execution on the workstation, compromising confidentiality, integrity, and availability of the client environment. The risk is heightened if automatic updates are enabled and the update source is not authenticated.

Generated by OpenCVE AI on August 13, 2026 at 01:55 UTC.

Remediation

Vendor Solution

The issues can be fixed by upgrading to version 1.1.9.14 or later.   See https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11046 7.5SJ11044 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11044 7.4SJ11045 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11045 7.3SJ11043 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11043


OpenCVE Recommended Actions

  • Upgrade IBM i Access Client Solutions to version 1.1.9.14 or later, following the vendor’s fix information links.
  • Restrict the client update source to a trusted and authenticated server; ensure that the update mechanism enforces code signing or checksum verification.
  • Disable automatic updates until the patch is applied, or apply the patch manually to prevent the client from retrieving unverified code.

Generated by OpenCVE AI on August 13, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:i_access_client_solutions:*:*:*:*:*:*:*:*

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.
Title IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
First Time appeared Ibm
Ibm i Access Client Solutions
Weaknesses CWE-494
CPEs cpe:2.3:a:ibm:i_access_client_solutions:1.1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i_access_client_solutions:1.1.9.13:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i Access Client Solutions
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm I Access Client Solutions
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T14:08:50.520Z

Reserved: 2026-06-26T14:37:01.533Z

Link: CVE-2026-13433

cve-icon Vulnrichment

Updated: 2026-08-13T14:08:45.876Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T21:17:35.380

Modified: 2026-08-18T14:46:08.517

Link: CVE-2026-13433

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:00:13Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check