Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.
Published: 2026-08-13
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability present in IBM i 7.6, 7.5, 7.4, and 7.3 permits a local attacker to bypass security controls by supplying a crafted LANG environment variable. This improper validation can lead to uncontrolled privilege escalation, allowing the attacker to run commands or services with elevated system privileges. The weakness is identified as CWE-73.

Affected Systems

Systems affected include IBM i releases 7.6, 7.5, 7.4, and 7.3 across all options that support the PASE environment. PTFs such as SJ10846 for 7.6, SJ10847 for 7.5, SJ10852 for 7.4, and SJ10854 for 7.3 provide the fix. Versions beyond 7.6 are not listed, so they are not known to be affected.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. The EPSS score is not available, so the likelihood of exploitation is uncertain, though its inclusion in the IBM advisory signals that the vendor considers it a serious issue. The vulnerability can be exploited by users who can set or influence the LANG variable on the system, typically via local interactive or scripted sessions. No public exploits are documented, and the vulnerability is not listed in the CISA KEV catalog, but IBM strongly recommends addressing it immediately.

Generated by OpenCVE AI on August 13, 2026 at 21:24 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 33 PTF Number(s)PTF Download Link(s)7.6SJ10846 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10846 7.5SJ10847 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10847 7.4SJ10852 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10852 7.3SJ10854 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10854 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM Technology PTFs (SJ10846, SJ10847, SJ10852, SJ10854) that address the improper LANG variable validation.
  • Upgrade any unsupported IBM i versions to a supported release that includes the fix.
  • Review, audit, and restrict the LANG environment variable in all user profiles and system services so that untrusted inputs cannot influence it.

Generated by OpenCVE AI on August 13, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.
Title IBM i is Affected By An Improper Validation Vulnerability in PASE []
First Time appeared Ibm
Ibm i
Weaknesses CWE-73
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:54:15.657Z

Reserved: 2026-07-24T08:45:44.450Z

Link: CVE-2026-16987

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T20:17:17.530

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-16987

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:30:11Z

Weaknesses
  • CWE-73

    External Control of File Name or Path