Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection.
Published: 2026-08-12
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from unsafe reflection in IBM i Navigator for i, permitting a remote authenticated attacker to bypass security restrictions. This flaw maps to CWE‑915 and can lead to unauthorized access or elevated privileges within the system, potentially compromising data confidentiality and integrity.

Affected Systems

Affected versions include IBM i 7.3, 7.4, 7.5, and 7.6. Patches are available as PTF SJ10891 for 7.3, SJ10890 for 7.4, SJ10888 for 7.5, and SJ10887 for 7.6. IBM advises users of unsupported versions to upgrade to a supported and fixed release.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity vulnerability. EPSS is not available, so the exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack requires remote authenticated access, and the unsafe reflection mechanism can be leveraged to defeat security controls if the vulnerability remains unpatched.

Generated by OpenCVE AI on August 12, 2026 at 23:38 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 3 PTF Number(s)PTF Download Link(s)7.6SJ10887 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10887 7.5SJ10888 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10888 7.4SJ10890 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10890 7.3SJ10891 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10891 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Install the PTF that corresponds to your IBM i release (SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, or SJ10891 for 7.3).
  • If the system is running an unsupported version of IBM i, upgrade to a supported release that includes the fix for unsafe reflection.
  • Reduce the use of reflection in the Navigator for i application and restrict authenticated user privileges to limit the impact of potential exploitation.

Generated by OpenCVE AI on August 12, 2026 at 23:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Thu, 13 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection.
Title IBM i is Affected By Multiple Vulnerabilities in Navigator for i
First Time appeared Ibm
Ibm i
Weaknesses CWE-915
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T16:27:38.452Z

Reserved: 2026-07-24T14:54:28.002Z

Link: CVE-2026-17095

cve-icon Vulnrichment

Updated: 2026-08-13T16:27:34.906Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T17:17:24.570

Modified: 2026-08-17T14:40:15.813

Link: CVE-2026-17095

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:45:03Z

Weaknesses
  • CWE-915

    Improperly Controlled Modification of Dynamically-Determined Object Attributes