Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management.
Published: 2026-08-13
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability permits an attacker who is already authenticated to a remote IBM i system to gain higher privileges than intended because the system does not enforce proper privilege boundaries when processing SQL statements. The flaw is a classic privilege escalation weakness identified as CWE-269, and it can compromise confidentiality and integrity of data and potentially lead to full system take‑over if an attacker can execute arbitrary privileged operations.

Affected Systems

IBM i releases 7.6, 7.5, 7.4, and 7.3 are affected. IBM has released public fixes (PTFs) for each release: SJ10823 for 7.6, SJ10822 for 7.5, SJ10821 for 7.4, and SJ10820 for 7.3. Users of unsupported versions are advised to upgrade to a supported, fixed version of IBM i.

Risk and Exploitability

The risk assessment shows a high CVSS score of 8.8 and no KEV listing, indicating that formal exploitation evidence is not yet documented. However, the vulnerability requires only that the attacker holds valid credentials to the SQL subsystem, after which the flaw can be leveraged. Because the exploitation path relies on authenticated access, internal threat actors or compromised user accounts pose the most immediate risk. The EPSS score is unavailable, so a precise probability estimate cannot be given, but the severity suggests that mitigation should not be deferred.

Generated by OpenCVE AI on August 13, 2026 at 21:31 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ10823 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10823 7.5SJ10822 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10822 7.4SJ10821 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10821 7.3SJ10820 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10820 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTF patch SJ10823 for release 7.6, or the corresponding PTF for your release (SJ10822 for 7.5, SJ10821 for 7.4, SJ10820 for 7.3).
  • If you are running an unsupported version, upgrade to a supported, fixed version of IBM i.
  • Review and restrict SQL user privileges, ensuring that only necessary accounts have higher privileges, and audit privilege assignments regularly.

Generated by OpenCVE AI on August 13, 2026 at 21:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management.
Title IBM i is Affected By An Unauthorized Privileges Vulnerability in SQL []
First Time appeared Ibm
Ibm i
Weaknesses CWE-269
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:40:28.878Z

Reserved: 2026-07-23T02:39:08.731Z

Link: CVE-2026-16722

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:15.057

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-16722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T20:30:02Z

Weaknesses
  • CWE-269

    Improper Privilege Management