Description
IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization of special elements used in an OS command.
Published: 2026-08-12
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an OS command injection flaw caused by failure to neutralize special elements in an OS command string. A remote authenticated attacker can exploit this flaw to run arbitrary commands with elevated system privileges, potentially compromising the confidentiality, integrity, and availability of the IBM i platform.

Affected Systems

IBM i versions 7.5 and 7.6 are affected. IBM recommends applying PTF SJ11010 for 7.5 and PTF SJ10931 for 7.6, or upgrading to a newer supported release if the current installation is unsupported.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The impact is limited to systems for which the attacker has authentication credentials; the attack vector is remote, requiring valid credentials to execute the injected commands.

Generated by OpenCVE AI on August 12, 2026 at 23:26 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 33 PTF Number(s)PTF Download Link(s)7.6SJ10931 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10931 7.5SJ11010 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11010 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM PTF SJ10931 to IBM i 7.6 or the PTF SJ11010 to IBM i 7.5 following IBM’s installation procedures.
  • If the current installation is unsupported, upgrade to the latest supported IBM i release that includes the fix.
  • As a temporary measure, restrict external network access to the IBM i system and enforce strict authentication controls to reduce the opportunity for an attacker to obtain credentials while the patch is applied.

Generated by OpenCVE AI on August 12, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization of special elements used in an OS command.
Title IBM i is Affected By Multiple Vulnerabilities in Domain Name System
First Time appeared Ibm
Ibm i
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-12T18:55:55.274Z

Reserved: 2026-07-24T06:16:23.681Z

Link: CVE-2026-16906

cve-icon Vulnrichment

Updated: 2026-08-12T18:55:51.639Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T18:17:24.773

Modified: 2026-08-13T16:48:00.187

Link: CVE-2026-16906

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:30:10Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')