Description
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable directory.
Published: 2026-08-13
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 contain a flaw that permits arbitrary code execution on Windows when the software is installed for all users. The installation process places a directory that is publicly writable into a location where the client automatically loads executables. By placing a malicious executable into that folder, an attacker can cause the client to run the file with the privileges of the user who installed the software, potentially enabling elevated actions if the installation runs under an administrator account. The weakness is classified as CWE‑426, an untrusted search path vulnerability.

Affected Systems

The vulnerability affects IBM i Access Client Solutions for Windows, specifically releases from version 1.1.2.0 up to and including 1.1.9.13, when the application is installed with the all‑users option. Installations that are per‑user do not expose this issue.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity level. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local: an attacker who can create a file in the publicly writable ACS directory will trigger execution automatically by the client. If the application runs under elevated privileges, the consequences become even more severe, potentially granting full control of the affected machine.

Generated by OpenCVE AI on August 13, 2026 at 21:01 UTC.

Remediation

Vendor Solution

The issues can be fixed by upgrading to version 1.1.9.14 or later.   See https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11046 7.5SJ11044 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11044 7.4SJ11045 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11045 7.3SJ11043 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11043


OpenCVE Recommended Actions

  • Upgrade IBM i Access Client Solutions to version 1.1.9.14 or later, following the IBM fix information links.
  • Reinstall the application with the per‑user option if possible, or otherwise restrict write permissions on the ACS installation directory so that only privileged accounts can modify it.
  • If reinstallation is not feasible immediately, remove or rename the publicly writable subdirectory that is scanned for executables.

Generated by OpenCVE AI on August 13, 2026 at 21:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable directory.
Title IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
First Time appeared Ibm
Ibm i Access Client Solutions
Weaknesses CWE-426
CPEs cpe:2.3:a:ibm:i_access_client_solutions:1.1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i_access_client_solutions:1.1.9.13:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i Access Client Solutions
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm I Access Client Solutions
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:38:29.458Z

Reserved: 2026-07-06T15:05:52.895Z

Link: CVE-2026-14875

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:14.390

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-14875

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:15:03Z

Weaknesses