Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management.
Published: 2026-08-13
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability stems from improper session management within IBM i’s Digital Certificate Manager, allowing a remote authenticated user to perform actions beyond their intended privileges and to retrieve sensitive information. The flaw is classified as CWE‑294, reflecting a weakness where session data can be misinterpreted or altered to bypass security controls. As a result, an attacker who has already authenticated can expand their access rights, potentially accessing or manipulating protected resources that they should not be able to touch.

Affected Systems

IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. The specific Patch Tracking Files that address this session‑management flaw are PTF SJ10907 for 7.6, PTF SJ10906 for 7.5, PTF SJ10905 for 7.4, and PTF SJ10904 for 7.3, each published as part of Option 34 for the respective release.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, and the vulnerability is exploitable remotely by an authenticated attacker who may obtain data or elevate privileges. EPSS data is not available, so the current measurable exploitation probability is unknown, yet the lack of a KEV listing suggests no widespread, actively used exploit is documented. Organizations running the affected IBM i releases should treat this as a high‑risk exposure and prioritize mitigating actions.

Generated by OpenCVE AI on August 13, 2026 at 21:52 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 34 PTF Number(s)PTF Download Link(s)7.6SJ10907 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10907 7.5SJ10906 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10906 7.4SJ10905 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10905 7.3SJ10904 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10904 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the appropriate PTF for your IBM i release (SJ10907 for 7.6, SJ10906 for 7.5, SJ10905 for 7.4, or SJ10904 for 7.3).
  • If a PTF is unavailable, suspend or remove the affected Digital Certificate Manager component until the fix is applied to prevent the session‑management flaw from being leveraged.
  • Validate that the patch restores proper session handling—monitor session logs for unauthorized operations after patching.

Generated by OpenCVE AI on August 13, 2026 at 21:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management.
Title IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager
First Time appeared Ibm
Ibm i
Weaknesses CWE-294
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:54:58.732Z

Reserved: 2026-07-24T13:10:32.777Z

Link: CVE-2026-17045

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:18.153

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-17045

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:30:05Z

Weaknesses
  • CWE-294

    Authentication Bypass by Capture-replay