Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.
Published: 2026-09-04
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive information disclosure
Action: Apply patch
AI Analysis

Impact

The vulnerability involves hardcoded cryptographic constants used to obfuscate encryption keys in IBM i versions 7.6, 7.5, 7.4, and 7.3. A remote attacker with authenticated access can exploit this flaw to recover sensitive data, potentially exposing confidential information.

Affected Systems

Affected installations include IBM i 7.6, 7.5, 7.4, and 7.3. The vendor recommends applying PTF SJ11156 for 7.6, SJ11159 for 7.5, SJ11158 for 7.4, and SJ11157 for 7.3, or upgrading to a supported release.

Risk and Exploitability

The impact is classified as moderate with a CVSS score of 4.4. The attack requires remote authenticated access; no publicly known exploit exists, and it is not listed in the KEV catalog. Although the EPSS score is not available, the presence of a known remote authentication vector suggests that organizations using these versions should treat the vulnerability as an actionable risk until the PTF is applied.

Generated by OpenCVE AI on September 4, 2026 at 17:57 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1 Option 34  PTF Number(s)PTF Download Link(s)7.6SJ11156 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11156 7.5SJ11159 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11159 7.4SJ11158 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11158 7.3SJ11157 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11157 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the PTFs SJ11156 (for 7.6), SJ11159 (for 7.5), SJ11158 (for 7.4), and SJ11157 (for 7.3) or upgrade to a supported, patched release of IBM i.
  • Verify that cryptographic configuration no longer relies on hardcoded constants; enforce use of strong, randomly generated keys.
  • Monitor logs for suspicious activity around encryption functions and alert on unauthorized access attempts.

Generated by OpenCVE AI on September 4, 2026 at 17:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.
Title IBM i is Affected By Cryptographic Algorithm Weakness in DCM []
First Time appeared Ibm
Ibm i
Weaknesses CWE-327
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T17:27:30.204Z

Reserved: 2026-07-23T01:05:28.552Z

Link: CVE-2026-16693

cve-icon Vulnrichment

Updated: 2026-09-04T17:27:23.328Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:52.390

Modified: 2026-09-08T17:29:28.200

Link: CVE-2026-16693

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T21:00:12Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm