Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.
Published: 2026-08-12
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in IBM i 7.6, 7.5, 7.4, and 7.3 allows a remote authenticated attacker to execute arbitrary system commands and retrieve sensitive data, yielding full control over the affected system and compromising confidentiality, integrity, and availability. The weakness is a classic privilege escalation flaw as identified by CWE‑250.

Affected Systems

IBM i (v7.3 through v7.6) is affected; the issue has been documented for all releases from 7.3 to 7.6 and manifests when the system is accessed with credentialed users who do not have proper privilege boundaries enforced.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, indicating high severity, and, although an EPSS score is not available, the lack of current exploitation records does not diminish the risk of an authenticated attacker exploiting this flaw. The threat is listed as not in the CISA KEV catalog, yet the high CVSS and authority recommendation to address immediately signify that the attack vector—remote authenticated access—poses a significant practical risk to organizations still running these versions.

Generated by OpenCVE AI on August 13, 2026 at 00:15 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10867 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10867 7.5SJ10868 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10868 7.4SJ10869 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10869 7.3SJ10870 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10870 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply IBM i fix pack PTFs: SJ10867 for 7.6, SJ10868 for 7.5, SJ10869 for 7.4, and SJ10870 for 7.3, following IBM’s installation guidance.
  • Review and tighten database user privileges, ensuring that only authorized accounts have access to SQL and system functions, and enforce least‑privilege principles for all users.
  • Enable comprehensive logging and audit trails for authenticated sessions and detect anomalous command executions to quickly identify potential exploitation attempts.

Generated by OpenCVE AI on August 13, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:i:*:*:*:*:*:*:*:*

Wed, 12 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.
Title IBM i is Affected By Multiple Vulnerabilities in SQL
First Time appeared Ibm
Ibm i
Weaknesses CWE-250
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-17T12:28:57.541Z

Reserved: 2026-07-24T15:40:46.862Z

Link: CVE-2026-17110

cve-icon Vulnrichment

Updated: 2026-08-17T12:26:47.202Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T18:17:25.717

Modified: 2026-08-17T13:16:51.323

Link: CVE-2026-17110

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T00:30:05Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges