Description
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Published: 2026-08-12
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from improper neutralization of special elements that are incorporated into operating system commands. A local attacker who can run the IBM i Access Client Solutions application can cause the system to execute arbitrary commands with the privileges of the user running the application, potentially leading to full control of the affected IBM i server.

Affected Systems

IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 are vulnerable. The affected installations run on IBM i systems and include all releases in that range.

Risk and Exploitability

The CVSS score of 7.8 signifies high severity; however, the flaw is local, meaning an attacker must have access to the target system or be able to log into the client application. EPSS data is not available, so the exploit probability cannot be quantified; the vulnerability is not listed in the CISA KEV catalog. The absence of remote exploitation barriers raises the risk level for environments where local users could exploit the client.

Generated by OpenCVE AI on August 13, 2026 at 02:53 UTC.

Remediation

Vendor Solution

The issues can be fixed by upgrading to version 1.1.9.14 or later. See IBM i Access Client Solutions updates for the latest version available. Product(s)Version(s)Remediation/Fix/Instructions IBM i Access Client Solutions1.1.2.0 - 1.1.9.13There are three ways to obtain the current version of IBM i Access Client Solutions: 1) IBM i Access Client Solutions is available at Downloads. 2) IBM i Access Client Solutions can be downloaded from the general IBM i software site at Entitled Systems Support (ESS). ID: LCD8-2010-43 3) IBM i Access Client Solutions is available by applying a PTF to IBM i. IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11046https://www.ibm.com/mysupport/s/fix-information?legacy=SJ110467.5SJ11044https://www.ibm.com/mysupport/s/fix-information?legacy=SJ110447.4SJ11045https://www.ibm.com/mysupport/s/fix-information?legacy=SJ110457.3SJ11043https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11043


OpenCVE Recommended Actions

  • Upgrade IBM i Access Client Solutions to version 1.1.9.14 or later
  • Apply the relevant IBM i PTFs (SJ11046, SJ11044, SJ11045, SJ11043) to IBM i Release 5770‑SS1
  • Restrict local user privileges to the IBM i Access Client Solutions application or disable the OS command execution feature if it is available

Generated by OpenCVE AI on August 13, 2026 at 02:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:i_access_client_solutions:*:*:*:*:*:*:*:*

Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Title IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
First Time appeared Ibm
Ibm i Access Client Solutions
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:i_access_client_solutions:1.1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i_access_client_solutions:1.1.9.13:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i Access Client Solutions
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm I Access Client Solutions
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:26:52.090Z

Reserved: 2026-07-23T01:12:25.223Z

Link: CVE-2026-16695

cve-icon Vulnrichment

Updated: 2026-08-13T19:21:21.286Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T21:17:36.427

Modified: 2026-08-18T19:00:11.090

Link: CVE-2026-16695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T03:00:09Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')