Description
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
Published: 2026-08-28
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper enforcement of authentication controls, allowing a remote authenticated attacker to bypass expected checks and gain access to sensitive information. Because the flaw enables an attacker who can present credentials to obtain data that should be restricted, the impact includes exposure of confidential data and the potential to exploit elevated privileges for further attacks on the system. The weakness is identified as a classic authentication bypass (CWE‑287).

Affected Systems

IBM Administration Runtime Expert for i on the IBM i platform, specifically the 1R1M0 release. This version is known to lack the necessary authentication enforcement that protects sensitive data and privileged operations.

Risk and Exploitability

The base score for this vulnerability is 7.5, indicating a high severity level. EPSS is not provided, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves a remote authenticated attacker leveraging user credentials or compromised accounts to exploit the denial of proper authentication. Because the flaw requires the attacker to be authenticated, mitigation is most effective by removing the vulnerability through the defined PTF rather than relying on generic monitoring or access controls alone.

Generated by OpenCVE AI on August 28, 2026 at 23:26 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Release5733-ARE PTF Number(s)PTF Download Link(s)V1R1M0 SJ11185 After applying this PTF the legacy ARE GUI is nonfunctional. https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11185


OpenCVE Recommended Actions

  • Apply the IBM PTF SJ11185 (V1R1M0) to address the authentication enforcement flaw
  • Once patched, verify that the legacy Administration Runtime Expert GUI has ceased functioning as a temporary protection measure
  • Enable logging and monitor authentication events to detect any anomalous credential use while the patch is being applied

Generated by OpenCVE AI on August 28, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
Title IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].
First Time appeared Ibm
Ibm administration Runtime Expert For I
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:administration_runtime_expert_for_i:1r1m0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm administration Runtime Expert For I
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Administration Runtime Expert For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-28T20:43:25.520Z

Reserved: 2026-07-24T19:21:38.713Z

Link: CVE-2026-17203

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:46.480

Modified: 2026-08-28T22:16:46.480

Link: CVE-2026-17203

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:30:17Z

Weaknesses