Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metacharacters.
Published: 2026-08-12
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a remote authenticated user to execute arbitrary commands on IBM i systems because shell metacharacters are not properly neutralized, enabling complete compromise of the affected system through command injection (CWE‑78).

Affected Systems

IBM i (IBM) versions 7.6, 7.5, 7.4, and 7.3 are affected. The advisory lists specific PTFs: SJ10968 for 7.6, SJ10966 for 7.4, and SJ10964 for 7.3. Users of unsupported releases should upgrade to a supported, fixed version of IBM i.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. No EPSS score is available and the flaw is not listed in the CISA KEV catalog. Exploitation requires remote authenticated access; once credentials are present, an attacker can run arbitrary shell commands. While authentication limits the threat to users or processes with valid credentials, the impact on confidentiality, integrity, and availability is severe.

Generated by OpenCVE AI on August 12, 2026 at 22:39 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10968 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10967 7.4SJ10966 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10966 7.3SJ10964 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10964 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTFs: SJ10968 for version 7.6, SJ10966 for version 7.4, and SJ10964 for version 7.3 (obtain the 7.5 fix from IBM support).
  • If your environment runs unsupported releases, upgrade to a supported, patched version of IBM i before addressing the flaw.
  • If immediate patching is not possible, restrict or disable remote authenticated access to the affected services until the fixes can be applied.

Generated by OpenCVE AI on August 12, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metacharacters.
Title IBM i is Affected By Remote Code Execution Vulnerabilities [, ]
First Time appeared Ibm
Ibm i
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T13:18:40.405Z

Reserved: 2026-07-25T05:46:26.881Z

Link: CVE-2026-17417

cve-icon Vulnrichment

Updated: 2026-08-13T13:18:33.563Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T20:17:40.170

Modified: 2026-08-17T17:50:46.413

Link: CVE-2026-17417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T22:45:10Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')