Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
Published: 2026-08-13
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i versions 7.3 through 7.6 contain a flaw in which an attacker who is locally authenticated can supply a malicious file path that bypasses validation checks. The vulnerability allows the attacker to alter the ownership of arbitrary files on the system, potentially granting them privilege escalation or enabling tampering with critical configuration files.

Affected Systems

Affected products include IBM i releases 7.3, 7.4, 7.5, and 7.6. Users running any of these versions are exposed to the risk; newer supported releases have addressed the issue.

Risk and Exploitability

The flaw drives a CVSS score of 7.8, indicating high severity, and is not listed in CISA's KEV catalog. Exploitation requires a local authenticated session and makes use of an improperly validated file path. Because the attack vector is local and the exploit is straightforward, the risk is significant for any system where users have the ability to interact with the file system. The absence of an EPSS score suggests current exploitation data is limited, but the high CVSS score warrants prompt attention.

Generated by OpenCVE AI on August 13, 2026 at 21:27 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11094 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11094 7.5SJ11093 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11093 7.4SJ11095 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11095 7.3SJ11096 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11096 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply IBM i Release5770-SS1 via the provided PTFs (SJ11094, SJ11093, SJ11095, and SJ11096) by downloading the patches from IBM and installing them according to the vendor’s instructions.
  • If operating on an unsupported IBM i release, upgrade to a supported, patched version before installing the release5770-SS1 patches.
  • Implement least‑privilege controls to restrict local users from changing file ownership, and apply stricter file‐path validation or policy enforcement if available.

Generated by OpenCVE AI on August 13, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
Title IBM i is Affected By Multiple Vulnerabilities in Network Authentication Service
First Time appeared Ibm
Ibm i
Weaknesses CWE-73
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:52:02.751Z

Reserved: 2026-07-24T05:38:28.286Z

Link: CVE-2026-16898

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:16.533

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-16898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:30:05Z

Weaknesses
  • CWE-73

    External Control of File Name or Path