Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
Published: 2026-09-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability is caused by a missing authentication requirement for critical NFS functions in IBM i 7.3, 7.4, 7.5, and 7.6, allowing a remote attacker to trigger a denial of service and potentially compromise data integrity. This flaw is classified as an authentication failure (CWE-306). The attack vector is remote, requiring the attacker to send unauthenticated requests to the NFS service.

Affected Systems

IBM i versions 7.3 through 7.6 are affected. Any configuration that exposes the NFS service without proper authentication is vulnerable, regardless of the operating environment.

Risk and Exploitability

The CVSS base score of 6.5 indicates medium severity, and the vulnerability is not listed in the KEV catalog. EPSS data is not available, so the probability of exploitation is unknown. The exploit requires network access to the NFS service and the ability to send unauthenticated requests, which can lead to service interruption and data corruption. Systems exposed to untrusted networks face a moderate risk.

Generated by OpenCVE AI on September 4, 2026 at 17:58 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ11320 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11320 7.5SJ11319 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11319 7.4SJ11318 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11318 7.3SJ11317 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11317 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770-SS1 PTF for your version (SJ11320 for 7.6, SJ11319 for 7.5, SJ11318 for 7.4, SJ11317 for 7.3).
  • Upgrade to a supported, fixed IBM i release if you are running an unsupported version.
  • If immediate patching is unavailable, block external access to the NFS service or enforce strict authentication controls around it.

Generated by OpenCVE AI on September 4, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
Title IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]
First Time appeared Ibm
Ibm i
Weaknesses CWE-306
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-08T17:32:21.706Z

Reserved: 2026-07-24T13:36:12.771Z

Link: CVE-2026-17057

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:52.893

Modified: 2026-09-08T18:17:35.417

Link: CVE-2026-17057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T00:00:06Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function