Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens.
Published: 2026-08-13
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In IBM i 7.6 through 7.3, a flaw in the Digital Certificate Manager allows a remote authenticated attacker to bypass the framework's anti‑CSRF token checks. This flaw, identified as CWE‑352, lets an attacker perform actions that the authenticated application would otherwise reject, potentially altering certificate configuration or revocation information. The vulnerability does not provide code execution but can be used to manipulate the system in ways that the user has not authorized.

Affected Systems

The affected product line is IBM i versions 7.6, 7.5, 7.4, and 7.3, all of which still expose the Digital Certificate Manager without the latest patches. IBM PTFs that address the issue are listed as SJ10907 for 7.6, SJ10906 for 7.5, SJ10905 for 7.4, and SJ10904 for 7.3. The vulnerability is present across all standard PTF levels (Option 34) and applies to product releases that contain this component.

Risk and Exploitability

The vulnerability has a CVSS score of 8.1, categorizing it as high severity. Because a valid authenticated session is required, the likelihood of exploitation depends on the attacker’s ability to obtain legitimate credentials. The EPSS score is not available, but the vulnerability is not listed in CISA’s KEV catalog, indicating that no public exploits have been confirmed. If the environment has exposed credentials or weak password policies, the risk rises markedly. Users should treat the flaw as a significant threat that requires immediate mitigation.

Generated by OpenCVE AI on August 13, 2026 at 21:21 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 34 PTF Number(s)PTF Download Link(s)7.6SJ10907 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10907 7.5SJ10906 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10906 7.4SJ10905 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10905 7.3SJ10904 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10904 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Download and apply the IBM PTF that matches your IBM i version (SJ10907 for 7.6, SJ10906 for 7.5, SJ10905 for 7.4, or SJ10904 for 7.3).
  • If an immediate patch cannot be installed, disable or limit access to the Digital Certificate Manager so that authenticated users cannot use the vulnerable component until the PTF is applied.
  • After the patch is deployed or the functionality restriction is in place, enable detailed audit logging for all certificate‑management operations and review logs for unauthorized changes.

Generated by OpenCVE AI on August 13, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens.
Title IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager
First Time appeared Ibm
Ibm i
Weaknesses CWE-352
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:55:20.545Z

Reserved: 2026-07-24T14:06:23.500Z

Link: CVE-2026-17069

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:18.303

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-17069

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:30:11Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)