Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management.
Published: 2026-08-13
Score: 4.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i systems running versions 7.6, 7.5, 7.4, and 7.3 on the LDAP interface can suffer from improper privilege management. This flaw enables a local attacker with sufficient access to the system to read sensitive data or modify protected objects. The weakness stems from a failure to correctly enforce access controls, categorized as CWE-269. The resulting damage includes confidentiality and integrity breaches, potentially allowing data exfiltration or unauthorized system changes.

Affected Systems

Affected vendor and product are IBM i. The affected versions are 7.6, 7.5, 7.4, and 7.3, as identified in the Industrial-grade CPE references. Any installation of these versions that interfaces with LDAP is considered vulnerable.

Risk and Exploitability

The CVSS score of 4.4 indicates a moderate risk, but the lack of an available EPSS score and absence from the CISA KEV catalog suggest that exploitation is not widely observed or documented. The flaw is exploitable only from a local context, requiring the attacker to already have some presence on the affected IBM i system. No public exploit code is known, and the vulnerability does not expose remote capabilities. Therefore, while the impact is significant for users with local administrative access, the likelihood of a widespread active compromise remains low at present.

Generated by OpenCVE AI on August 13, 2026 at 22:44 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ10919 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10919 7.5SJ10989 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10989 7.4SJ10991 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10991 7.3SJ10992 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10992 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770-SS1 patch set and install the product fix tags (PTFs) specific to your version: SJ10919 for 7.6, SJ10989 for 7.5, SJ10991 for 7.4, and SJ10992 for 7.3.
  • If your IBM i deployment is on an unsupported version, upgrade to the latest supported release that includes the fixed LDAP privilege management logic.
  • Until the official patch or upgrade is applied, restrict local user access to the LDAP interface using role‑based access controls, limiting privileged operations to only those users that absolutely require them.

Generated by OpenCVE AI on August 13, 2026 at 22:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management.
Title IBM i is Affected By An Improper Privilege Management Vulnerability in LDAP []
First Time appeared Ibm
Ibm i
Weaknesses CWE-269
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:37:39.045Z

Reserved: 2026-07-25T15:41:41.797Z

Link: CVE-2026-17438

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:42.810

Modified: 2026-08-13T21:17:42.810

Link: CVE-2026-17438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management