Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a time-of-check time-of-use (TOCTOU) race condition.
Published: 2026-08-13
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a time‑of‑check to time‑of‑use race condition in IBM i’s Network Authentication Service that permits an attacker who is locally authenticated to gain unauthorized access to protected files. This flaw can lead to confidentiality violations by allowing reading, altering, or executing files that the attacker should not have permission to access. The weakness is identified as CWE‑367.

Affected Systems

IBM i versions 7.3, 7.4, 7.5, and 7.6 are vulnerable. The affected components are the Network Authentication Service policies and file access control routines. Only supported releases of IBM i are corrected by forthcoming Release5770‑SS1 patch and corresponding PTFs for each platform.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, while the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack requires local authenticated access, meaning it is primarily exploitable by users who already have system login credentials. The race condition in the service’s file access checks can be triggered without additional privilege escalation, making it a serious risk for systems where users have higher‑than‑necessary file permissions and where the IBM i patches are not yet applied.

Generated by OpenCVE AI on August 13, 2026 at 21:27 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11094 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11094 7.5SJ11093 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11093 7.4SJ11095 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11095 7.3SJ11096 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11096 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply IBM i Release5770‑SS1 for your platform, which includes the necessary PTFs (SJ11094 for 7.6, SJ11093 for 7.5, SJ11095 for 7.4, SJ11096 for 7.3).
  • Restrict local authenticated users to the minimum file permissions required for their roles until the patch can be installed.
  • Monitor system access logs for unusual file access attempts and ensure the Network Authentication Service configuration follows least privilege principles.

Generated by OpenCVE AI on August 13, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a time-of-check time-of-use (TOCTOU) race condition.
Title IBM i is Affected By Multiple Vulnerabilities in Network Authentication Service
First Time appeared Ibm
Ibm i
Weaknesses CWE-367
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:51:47.156Z

Reserved: 2026-07-24T05:30:57.905Z

Link: CVE-2026-16896

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:16.400

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-16896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:30:05Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition