Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.
Published: 2026-09-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Local)
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises because IBM i incorrectly validates FTP authentication commands, allowing an attacker with local access to send crafted inputs that lead to a denial of service. The improper command validation can cause the FTP service to fail or become unresponsive, effectively disrupting applications that rely on file transfers. The weakness corresponds to command injection style flaws (CWE‑78) and results in loss of availability for the affected system.

Affected Systems

Affected components are IBM i operating systems – specifically releases 7.6, 7.5, 7.4, and 7.3. Systems running any of these versions are at risk until the appropriate product fix (patches SJ11371 for 7.6, SJ11382 for 7.5, SJ11383 for 7.4, or SJ11384 for 7.3) is applied. The vulnerability is limited to the local scope and affects the FTP service and any processes that interact with it.

Risk and Exploitability

The CVSS base score is 5.4, indicating a moderate impact when exploited. Because the flaw requires local access, the attack vector is limited to users who can execute commands or maintain privileged console access on the IBM i host. The EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known large‑scale exploitation. Nonetheless, any local attacker who can send malformed FTP authentication requests can trigger a crash or hang of the FTP service, causing downtime until the patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 10:46 UTC.

Remediation

Vendor Solution

IBM i Release5770-TC1  PTF Number(s)PTF Download Link(s)7.6SJ11371 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11371 7.5SJ11382 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11382 7.4SJ11383 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11383 7.3SJ11384 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11384 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Download and install the IBM i Release5770‑TC1 patch for your specific version; for example, use SJ11371 for 7.6, SJ11382 for 7.5, SJ11383 for 7.4, or SJ11384 for 7.3.
  • After installation, restart the FTP service (ftpd) or reboot the IBM i system to ensure the patch takes effect and verify that the FTP service responds to basic commands.
  • While the patches are pending or for temporary protection, restrict or disable the FTP service for local users, or limit the access rights of local accounts that can issue FTP commands.

Generated by OpenCVE AI on September 19, 2026 at 10:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.
Title IBM i is Affected By Denial of Service and Security Restriction Bypass Vulnerabilities in FTP [, ]
First Time appeared Ibm
Ibm i
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-23T03:55:35.395Z

Reserved: 2026-07-24T22:36:41.742Z

Link: CVE-2026-17262

cve-icon Vulnrichment

Updated: 2026-09-19T14:07:59.505Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:09.933

Modified: 2026-09-23T04:17:41.683

Link: CVE-2026-17262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:00:21Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')