Description
IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action.
Published: 2026-09-14
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Command Execution as Authenticated User
Action: Patch Now
AI Analysis

Impact

IBM i Access Client Solutions (i Access Family) versions 1.1.2.0 through flaw in the RunProgram macro of the emulator. Improper validation of user‑supplied input allows an authenticated user to supply a macro that triggers the execution of arbitrary shell commands with the same privilege level as the user. The vulnerability is therefore a command‑execution weakness (CWE‑78) that can be leveraged to run malicious instructions within the context of a valid account.

Affected Systems

Affected systems are IBM i Access Family client solutions on IBM i platforms. The CVE impacts all installations from version 1.1.2.0 up to and including 1.1.9.15; no other releases are known to be affected.

Risk and Exploitability

The CVSS base score is 6.3, indicating a moderate likelihood of exploitation. The EPSS score of less than 1% suggests a very low probability of being targeted in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to have valid credentials that permit macro execution; the attack vector is therefore local or remote with authentication, and the malicious macro can run arbitrary commands under the user’s rights.

Generated by OpenCVE AI on September 17, 2026 at 19:21 UTC.

Remediation

Vendor Solution

The issues can be fixed by upgrading to version 1.1.9.16 or later.   See https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11504 7.5SJ11505 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11505 7.4SJ11506 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11506 7.3SJ11507 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11507


OpenCVE Recommended Actions

  • Upgrade IBM i Access Family to version 1.1.9.16 or later to address the flaw, following the vendor’s fix information pages for 7.5, 7.4, and 7.3 releases.
  • If an upgrade cannot be applied immediately, disable the RunProgram macro capability or restrict its use to trusted users only, thereby preventing the malicious macro path from being executed.
  • Configure the emulator or macro execution environment to enforce strict input validation and sanitize all user‑supplied parameters, which mitigates the risk of command injection even if the macro feature remains enabled.

Generated by OpenCVE AI on September 17, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action.
Title IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
First Time appeared Ibm
Ibm i Access Family
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:i_access_family:1.1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i_access_family:1.1.9.15:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i Access Family
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Ibm I Access Family
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-17T12:00:29.011Z

Reserved: 2026-06-30T19:55:37.357Z

Link: CVE-2026-14276

cve-icon Vulnrichment

Updated: 2026-09-15T17:38:37.515Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:02.413

Modified: 2026-09-17T12:17:24.110

Link: CVE-2026-14276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')