Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.
Published: 2026-09-04
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote authentication bypass of security restrictions
Action: Patch
AI Analysis

Impact

IBM i systems version 7.3 through 7.6 have a flaw where an authenticated attacker can exploit predictable server seed values to bypass defined security restrictions. The vulnerability allows the attacker to elevate privileges beyond intended levels within the debug server context, potentially accessing or modifying sensitive data or configuration. The flaw is a classic authorization bypass, classified under CWE-330.

Affected Systems

IBM i 7.6, IBM i 7.5, IBM i 7.4, and IBM i 7.3 are impacted. The issue exists in the debug server component of these operating system editions, and only machines running these versions without the appropriate fixes are vulnerable.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate risk. There is no EPSS score available, and the vulnerability has not been listed in the CISA KEV catalog. The attack requires remote authenticated access to the debug server, suggesting that compromised or privileged credentials could be used to exploit the predictable server seeds. If exploited, the attacker can escape the security model imposed by IBM i, potentially impacting confidentiality, integrity, or availability of system data.

Generated by OpenCVE AI on September 4, 2026 at 18:01 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11305 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11305 7.5SJ11306 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11306 7.4SJ11307 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11307 7.3SJ11308 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11308 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770-SS1 point release and install the PTFs listed for each affected version (SJ11305, SJ11306, SJ11307, SJ11308).
  • Disable the debug server feature for users and services that do not require it, or restrict its use to trusted hosts only.
  • Enforce strong authentication and regularly review user permissions that can access the debug server to ensure only necessary accounts have access.

Generated by OpenCVE AI on September 4, 2026 at 18:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.
Title IBM i is Affected By Multiple Vulnerabilities in Debug Server
First Time appeared Ibm
Ibm i
Weaknesses CWE-330
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-08T17:31:24.741Z

Reserved: 2026-07-24T23:31:13.521Z

Link: CVE-2026-17274

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:53.710

Modified: 2026-09-09T14:22:00.690

Link: CVE-2026-17274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T00:00:06Z

Weaknesses
  • CWE-330

    Use of Insufficiently Random Values