Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.
Published: 2026-08-13
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper validation of authentication tokens in IBM i's Digital Certificate Manager. A remote attacker who can control the token handling process may obtain confidential data and trigger privileged operations. The flaw maps to CWE‑287, which describes incorrect verification of credentials, allowing attackers to bypass intended restrictions because the system relies on token integrity to grant access.

Affected Systems

IBM i releases 7.3, 7.4, 7.5, and 7.6 are affected. The affected product is IBM i in all its supported releases within these major version numbers. The PTFs that address the flaw are SJ10904 for 7.3, SJ10905 for 7.4, SJ10906 for 7.5, and SJ10907 for 7.6.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.5, indicating moderate severity. EPSS data is not available and the flaw is not listed in CISA’s KEV catalog. The attack vector is remote and exploits the ability to supply crafted authentication tokens to the Digital Certificate Manager. While no public exploit has been disclosed, the potential for unauthorized data access or administrative operation execution warrants prompt remediation.

Generated by OpenCVE AI on August 13, 2026 at 22:44 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 34 PTF Number(s)PTF Download Link(s)7.6SJ10907 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10907 7.5SJ10906 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10906 7.4SJ10905 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10905 7.3SJ10904 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10904 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the PTF that matches your IBM i release (SJ10904 for 7.3, SJ10905 for 7.4, SJ10906 for 7.5, or SJ10907 for 7.6).
  • If operating on an unsupported IBM i version, upgrade to a supported release that includes the fix.
  • Reconfigure the Digital Certificate Manager and related authorization mechanisms to enforce strict token validation, ensuring that only tokens issued by trusted sources are accepted.

Generated by OpenCVE AI on August 13, 2026 at 22:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.
Title IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager
First Time appeared Ibm
Ibm i
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:35:49.998Z

Reserved: 2026-07-24T14:19:43.595Z

Link: CVE-2026-17075

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:41.390

Modified: 2026-08-13T21:17:41.390

Link: CVE-2026-17075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:45:03Z

Weaknesses