Impact
This vulnerability is an out‑of‑bounds read in the NetServer component of IBM i. A remote authenticated attacker can leverage the flaw to read sensitive information or trigger a denial of service. The weakness is a classic example of buffer boundary errors, which can expose confidential data to the attacker or disrupt service availability.
Affected Systems
IBM i releases 7.6, 7.5, 7.4, and 7.3 are affected, covering all major release lines prior to the July 2026 fix. The specific PTFs that contain the repair are MJ10939 for 7.6, MJ10938 for 7.5, MJ10937 for 7.4, and MJ10936 for 7.3. Systems running these versions without the corresponding updates are at risk.
Risk and Exploitability
The issue carries a CVSS score of 5.4, indicating a medium severity level. No EPSS score is available, but the description specifies that a remote authenticated user is required to exploit the flaw, which limits the attacker pool to those with valid credentials. The vulnerability is not in the CISA KEV catalog, so it is unlikely to be actively targeted yet. Nonetheless, the potential for data leakage or service interruption warrants immediate patching.
OpenCVE Enrichment