Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper privilege management.
Published: 2026-08-13
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i 7.6, 7.5, 7.4, and 7.3 contain a flaw that allows a remote authenticated attacker to bypass security restrictions by escalating privileges. The vulnerability stems from improper privilege management and enables the attacker to gain higher levels of access than authorized, potentially revealing or modifying protected data and system configuration.

Affected Systems

The affected system is IBM i for versions 7.3, 7.4, 7.5, and 7.6. Each version can be identified by its major release number and may be updated using the corresponding PTFs listed in the advisory.

Risk and Exploitability

The CVSS score of 3.1 indicates a low severity overall, and no exploit probability has been published in EPSS. The vulnerability is not currently listed in CISA’s KEV catalog. The attack requires a valid authenticated session to IBM i, and the attacker must possess at least basic user privileges. Once authenticated, the attacker can exploit the privilege escalation to assume higher rights, potentially leading to unauthorized access to sensitive information or system control if combined with other weaknesses.

Generated by OpenCVE AI on August 13, 2026 at 21:50 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ10848 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10848 7.5SJ10849 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10849 7.4SJ10850 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10850 7.3SJ10851 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10851 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770-SS1 update and the relevant PTFs (SJ10848 for 7.6, SJ10849 for 7.5, SJ10850 for 7.4, SJ10851 for 7.3) to all affected IBM i systems.
  • Restrict access to DRDA and DDM services by configuring firewall rules or network segmentation to limit connections to trusted hosts only.
  • Enforce least‑privilege access controls by reviewing user roles and removing unnecessary privileges that could be leveraged by an authenticated attacker.

Generated by OpenCVE AI on August 13, 2026 at 21:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper privilege management.
Title IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM
First Time appeared Ibm
Ibm i
Weaknesses CWE-269
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:25:14.772Z

Reserved: 2026-07-24T14:17:00.053Z

Link: CVE-2026-17074

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:41.263

Modified: 2026-08-13T21:17:41.263

Link: CVE-2026-17074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:15:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management