Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted search path.
Published: 2026-08-13
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An untrusted search path vulnerability (CWE‑426) in WebSphere Application Server Liberty running on IBM i allows a remote authenticated attacker to execute arbitrary code. The flaw permits execution of code that an attacker can supply by manipulating the search path used by the server. This capability can lead to full compromise of the IBM i system where the attacker controls code execution on the host.

Affected Systems

IBM i releases 7.6, 7.5, 7.4, and 7.3 are affected. The error is present in the WebSphere Application Server Liberty component on these releases. IBM provides Product Temporary Fixes (PTFs) for each release: 7.6 requires PTFs SJ10874 and SJ11023, 7.5 requires SJ10875 and SJ11024, 7.4 requires SJ10876 and SJ11025, and 7.3 requires SJ10877 and SJ11026. Users of unsupported or older IBM i versions should consider upgrading to a supported release that includes the fix.

Risk and Exploitability

The CVSS score of 8.8 categorizes this flaw as high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, indicating there is no publicly known exploitation activity at the time of this analysis. The likely attack vector involves a remote authenticated attacker that can send inputs to WebSphere Application Server Liberty. IBM explicitly recommends that users address the vulnerability immediately, implying a significant risk if patches are not applied.

Generated by OpenCVE AI on August 13, 2026 at 21:31 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 3 PTF Number(s)PTF Download Link(s)7.6SJ10874 SJ11023 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10874 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11023 7.5SJ10875 SJ11024 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10875 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11024 7.4SJ10876 SJ11025 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10876 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11025 7.3SJ10877 SJ11026 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10877 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11026 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTF updates SJ10874 and SJ11023 for the 7.6 release, SJ10875 and SJ11024 for 7.5, SJ10876 and SJ11025 for 7.4, and SJ10877 and SJ11026 for 7.3. The PTFs are available from IBM’s support site and fix the untrusted search path issue.
  • Upgrade to the latest supported IBM i release that incorporates the WebSphere Application Server Liberty fix, ensuring that both the operating system and Liberty are at the most recent patched level.
  • If immediate patching is impractical, restrict exposure by disabling or limiting remote services that allow authentication to WebSphere Application Server Liberty and enforce least privilege on any remaining access.

Generated by OpenCVE AI on August 13, 2026 at 21:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted search path.
Title IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty
First Time appeared Ibm
Ibm i
Weaknesses CWE-426
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:38:51.104Z

Reserved: 2026-07-22T20:02:22.059Z

Link: CVE-2026-16674

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:14.527

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-16674

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T20:30:02Z

Weaknesses