Description
IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command.
Published: 2026-09-14
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Command execution with normal user privileges
Action: Apply Patch
AI Analysis

Impact

IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.15 allow an authenticated user to execute arbitrary commands on the system due to improper validation of user-supplied command. The flaw is a classic command injection vulnerability (CWE‑78) that permits a user to run any command that their account is permitted to execute on the target machine.

Affected Systems

The vulnerability affects the IBM i Access Family product line. Any installation of IBM i Access Client Solutions with a version number between 1.1.2.0 and 1.1.9.15 inclusive is impacted. Upgrading to version 1.1.9.16 or later resolves the issue.

Risk and Exploitability

The CVSS score of 6.3 categorizes the vulnerability as medium severity. The exploit probability (EPSS) is currently low at < 1%, and the vulnerability is not listed in the CISA KEV catalog. An attacker who can authenticate to the system can supply malicious input to the STRPCCMD command, causing the system to execute arbitrary commands with the privileges of the authenticated user. This can lead to privilege abuse or facilitate further lateral movement or persistence, depending on the user account’s permissions and other system configurations.

Generated by OpenCVE AI on September 17, 2026 at 19:21 UTC.

Remediation

Vendor Solution

The issues can be fixed by upgrading to version 1.1.9.16 or later.   See https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11504 7.5SJ11505 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11505 7.4SJ11506 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11506 7.3SJ11507 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11507


OpenCVE Recommended Actions

  • Upgrade IBM i Access Client Solutions to version 1.1.9.16 or later as supplied by IBM.
  • If immediate upgrade is not possible, restrict the privileges of accounts that have access to the STRPCCMD command to limit the commands they can run.
  • Enable auditing of CL command usage and monitor for unexpected STRPCCMD invocations to detect potential exploitation.

Generated by OpenCVE AI on September 17, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command.
Title IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
First Time appeared Ibm
Ibm i Access Family
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:i_access_family:1.1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i_access_family:1.1.9.15:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i Access Family
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Ibm I Access Family
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-17T12:00:41.524Z

Reserved: 2026-06-30T19:50:50.163Z

Link: CVE-2026-14275

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:46.571Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:02.273

Modified: 2026-09-17T12:17:23.973

Link: CVE-2026-14275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')