Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.
Published: 2026-08-13
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i systems running releases 7.3 through 7.6 are vulnerable to an authentication flaw in NTLM session negotiation. An attacker who can reach the NetServer service may cause the system to accept a forged authentication request, thereby gaining access to server resources with the privileges of an authenticated user. This flaw is identified as CWE‑287 and is quantified with a CVSS score of 8.1, indicating a high severity risk of potential full system compromise.

Affected Systems

Affected products include IBM i releases 7.3, 7.4, 7.5, and 7.6. IBM has issued PTFs for each release: MJ10936 for 7.3, MJ10937 for 7.4, MJ10938 for 7.5, and MJ10939 for 7.6, which address the improper authentication issue.

Risk and Exploitability

The CVSS score of 8.1 reflects a significant threat, and although an EPSS score is not available, the lack of an EPSS metric does not indicate absence of exploitation potential. The vulnerability is not listed in the CISA KEV catalog, but the remote nature of the exploit – through the NetServer service – means that any host with network connectivity to the server could potentially leverage the flaw. Immediate application of the relevant PTF or upgrade to a supported release is essential to eliminate this high‑risk authentication bypass.

Generated by OpenCVE AI on August 13, 2026 at 21:30 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-999 PTF Number(s)PTF Download Link(s)7.6MJ10939 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10939 7.5MJ10938 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10938 7.4MJ10937 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10937 7.3MJ10936 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ10936 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Download and install the PTF matching your IBM i release (MJ10939 for 7.6, MJ10938 for 7.5, MJ10937 for 7.4, MJ10936 for 7.3).
  • Restrict NetServer traffic to trusted hosts or clients by configuring firewall rules and ensuring that only authorized users can initiate NTLM sessions.
  • Upgrade any unsupported IBM i releases to a supported, patched version and maintain a regular patch management schedule to prevent similar authentication weaknesses from re‑appearing.

Generated by OpenCVE AI on August 13, 2026 at 21:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.
Title IBM i is Affected By Multiple Vulnerabilities in NetServer
First Time appeared Ibm
Ibm i
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:50:34.444Z

Reserved: 2026-07-24T04:14:10.235Z

Link: CVE-2026-16867

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:15.723

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-16867

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:30:11Z

Weaknesses