Description
IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.
Published: 2026-09-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of system messages
Action: Patch
AI Analysis

Impact

IBM i 7.6, 7.5, and 7.4 contain an improper authorization flaw that allows a remote authenticated attacker to alter certain system messages, compromising the integrity of system logging and notifications.

Affected Systems

The vulnerability affects IBM i releases 7.4, 7.5, and 7.6. These releases are addressed by IBM i Release 5770‑SS1. The specific PTFs for each version are SJ11201 for 7.6, SJ11210 for 7.5, and SJ11211 for 7.4.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. The attack vector is remote, requiring authentication on the IBM i system, which indicates the need for strong access controls and timely patching.

Generated by OpenCVE AI on September 4, 2026 at 17:58 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ11201 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11201 7.5SJ11210 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11210 7.4SJ11211 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11211 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Download and apply the PTF for your IBM i release (SJ11201 for 7.6, SJ11210 for 7.5, SJ11211 for 7.4) from IBM support.
  • If you are running an unsupported IBM i version, upgrade to a supported release that includes the fix.
  • Coordinate with system administrators to enforce restrictive permissions on system messages until the patch is applied.

Generated by OpenCVE AI on September 4, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.
Title IBM i is Affected By An Incorrect Authorization Vulnerability []
First Time appeared Ibm
Ibm i
Weaknesses CWE-863
CPEs cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:00:33.764Z

Reserved: 2026-07-24T07:52:09.302Z

Link: CVE-2026-16941

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:52.770

Modified: 2026-09-10T21:17:20.067

Link: CVE-2026-16941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T22:45:03Z

Weaknesses