Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.
Published: 2026-08-12
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a remote authenticated attacker to gain higher privileges due to improper authorization when handling high‑authority threads. The flaw could enable the attacker to execute functions with elevated rights, potentially leading to full system compromise. The weakness is classified as CWE‑269.

Affected Systems

Affected IBM i releases include 7.6, 7.5, 7.4, and 7.3. For version 7.6 the fix is available as PTF SJ10887, for 7.5 as SJ10888, for 7.4 as SJ10890, and for 7.3 as SJ10891. Systems should ensure they apply the corresponding patch or upgrade to a supported release that includes the fix.

Risk and Exploitability

The CVSS v3.1 base score is 9.6, indicating a critical severity. The EPSS score is not available, but the lack of a KEV listing does not reduce the risk; a remote authenticated attacker can exploit the flaw. Proper remediation is essential to prevent attackers from escalating privileges on the system.

Generated by OpenCVE AI on August 12, 2026 at 22:46 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 3 PTF Number(s)PTF Download Link(s)7.6SJ10887 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10887 7.5SJ10888 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10888 7.4SJ10890 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10890 7.3SJ10891 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10891 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTF(s) appropriate for your release (SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, SJ10891 for 7.3).
  • If running an unsupported IBM i release, upgrade to a supported release that incorporates this fix.
  • Limit user permissions to restrict the creation of high‑authority threads and monitor system logs for any abnormal privilege escalation attempts.

Generated by OpenCVE AI on August 12, 2026 at 22:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:i:*:*:*:*:*:*:*:*

Thu, 13 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.
Title IBM i is Affected By Multiple Vulnerabilities in Navigator for i
First Time appeared Ibm
Ibm i
Weaknesses CWE-269
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-12T19:18:31.054Z

Reserved: 2026-07-24T23:48:20.751Z

Link: CVE-2026-17276

cve-icon Vulnrichment

Updated: 2026-08-12T17:58:31.295Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T18:17:26.680

Modified: 2026-08-13T16:28:39.813

Link: CVE-2026-17276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:00:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management