Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.
Published: 2026-09-04
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Apply patch
AI Analysis

Impact

The vulnerability arises from improper authentication during service‑name matching in IBM i's Network Authentication Service. A remote attacker who can authenticate to the system may bypass intended security restrictions, potentially gaining elevated access or manipulating protected resources. This flaw is classified as CWE‑287, underscoring its foundation in flawed authentication logic.

Affected Systems

Affected systems include IBM i releases 7.3, 7.4, 7.5, and 7.6. The specific product is IBM i, and the impact covers all versions listed. Each of these legacy releases is vulnerable until the corresponding IBM PTF is applied.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, though the EPSS score is not available, making it difficult to assess current exploitation likelihood. The vulnerability is not yet listed in CISA's KEV catalog. Exploitation requires the attacker to possess valid credentials, but once authenticated the attacker can exploit the flaw to circumvent access controls. Prioritizing patch deployment is therefore critical.

Generated by OpenCVE AI on September 4, 2026 at 17:58 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ11089 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11089 7.5SJ11090 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11090 7.4SJ11091 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11091 7.3SJ11092 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11092 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Download and install the IBM i PTF that applies to your release (SJ11089 for 7.6, SJ11090 for 7.5, SJ11091 for 7.4, or SJ11092 for 7.3).
  • Restart the Network Authentication Service or reboot the system to apply the new authentication logic.
  • If your environment runs an unsupported IBM i version, plan an upgrade to a supported release that includes the fix as part of IBM's supported path.

Generated by OpenCVE AI on September 4, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.
Title IBM i is Affected By An Improper Authentication Vulnerability in Network Authentication Service []
First Time appeared Ibm
Ibm i
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T17:31:59.322Z

Reserved: 2026-07-24T05:14:10.271Z

Link: CVE-2026-16892

cve-icon Vulnrichment

Updated: 2026-09-04T17:31:55.667Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:52.643

Modified: 2026-09-08T17:25:26.963

Link: CVE-2026-16892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T21:00:12Z

Weaknesses