Description
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-08-12
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a stored cross‑site scripting flaw in the IBM i Web UI. An attacker who is authenticated to the system can insert arbitrary JavaScript that is subsequently executed by other users browsing the UI. The injected script can manipulate the UI and potentially read session data, leading to disclosure of credentials within a trusted session. The weakness corresponds to CWE‑79.

Affected Systems

IBM i versions 7.6, 7.5, 7.4 and 7.3 are affected. To remediate, IBM recommends installing the PTFs Sj10887, Sj10888, Sj10890 and Sj10891 respectively, which can be downloaded from IBM Fix Central.

Risk and Exploitability

The CVSS score is 6.4, indicating a moderate severity. Exploit probability is not publicly available, and the vulnerability has not been listed in the CISA KEV catalog. The likely attack vector requires an authenticated session and local or remote access to the Web UI, but unauthenticated users cannot inject malicious code. As a result, the risk is moderate and the vulnerability is best mitigated by applying the vendor patches.

Generated by OpenCVE AI on August 12, 2026 at 22:47 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 3 PTF Number(s)PTF Download Link(s)7.6SJ10887 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10887 7.5SJ10888 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10888 7.4SJ10890 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10890 7.3SJ10891 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10891 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Install and apply the IBM i PTF corresponding to your release; the official fix eliminates the stored XSS flaw.
  • Reboot the system when required by the PTF installation instructions and verify that the Web UI functions normally afterward.
  • Restrict authenticated access to the Web UI to only privileged users and enforce least‑privilege policies to limit exposure.
  • If patching is delayed, isolate the Web UI from external networks and monitor access logs for suspicious activity until the fix is applied.

Generated by OpenCVE AI on August 12, 2026 at 22:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM i is Affected By Stored Cross-site Scripting for i
First Time appeared Ibm
Ibm i
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-12T19:19:06.081Z

Reserved: 2026-07-23T01:09:25.972Z

Link: CVE-2026-16694

cve-icon Vulnrichment

Updated: 2026-08-12T17:11:40.965Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T17:17:23.993

Modified: 2026-08-17T14:27:44.660

Link: CVE-2026-16694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')