Description
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Published: 2026-08-12
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An SQL injection flaw exists in IBM i version 7.3 through 7.6 that lets a remote attacker craft malicious SQL commands. The attacker could read, insert, modify, or delete records in the backend database, effectively compromising data confidentiality, integrity, and availability. The weakness is a classic injection flaw classified as CWE-89.

Affected Systems

IBM i operating systems releases 7.3, 7.4, 7.5, and 7.6 are affected. Users of any of these versions should apply the relevant Product Fixes (PTFs) – for example SJ10867 for 7.6, SJ10868 for 7.5, SJ10869 for 7.4, and SJ10870 for 7.3 – or upgrade to a newer, supported release that includes the fix.

Risk and Exploitability

The CVSS score of 7.6 indicates high severity, while the EPSS value is not available, so the exact likelihood of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog, but it is a remote exploit that can be triggered without local access. Given that the flaw allows critical database operations, the potential impact remains significant.

Generated by OpenCVE AI on August 12, 2026 at 22:38 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10867 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10867 7.5SJ10868 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10868 7.4SJ10869 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10869 7.3SJ10870 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10870 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTFs listed on IBM’s support site for each affected release (SJ10867, SJ10868, SJ10869, or SJ10870).
  • If the installed IBM i version is no longer supported, upgrade to the latest stable release that includes the fix.
  • Implement network segmentation and monitor database access logs for unusual query patterns that could indicate injection attempts.

Generated by OpenCVE AI on August 12, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Wed, 12 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Title IBM i is Affected By Multiple Vulnerabilities in SQL
First Time appeared Ibm
Ibm i
Weaknesses CWE-89
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-12T20:54:26.706Z

Reserved: 2026-07-24T15:44:17.208Z

Link: CVE-2026-17111

cve-icon Vulnrichment

Updated: 2026-08-12T20:35:54.806Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T20:17:39.497

Modified: 2026-08-17T17:51:20.620

Link: CVE-2026-17111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T22:45:10Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')