Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Published: 2026-09-04
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Command Execution
Action: Patch
AI Analysis

Impact

The vulnerability is a command‑injection flaw in the IBM i debug server caused by insufficient neutralization of special characters in operating‑system commands. A local attacker who can reach the debug server can supply crafted input that results in arbitrary command execution with the privileges of the server process. This allows full compromise of confidentiality, integrity, and availability on the affected system, and can be leveraged to gain elevated privileges, effectively turning the operating system into an attacker‑controlled machine.

Affected Systems

The flaw affects IBM i versions 7.3, 7.4, 7.5, and 7.6. IBM has provided PTFs to address the issue: SJ11308 for 7.3, SJ11307 for 7.4, SJ11306 for 7.5, and SJ11305 for 7.6. Systems running these releases are susceptible unless they are upgraded to the supported release IBM i Release 5770‑SS1 or have the specific PTF applied.

Risk and Exploitability

The vulnerability has a CVSS score of 4.4, which indicates moderate severity, and no EPSS data is available; it is not listed in the CISA KEV catalog. Because the attack requires local access to the debug server, the exploitability is limited to users with physical or local network access, and the likelihood of widespread exploitation is low. However, once a local attacker gains a foothold, arbitrary command execution and privilege escalation can occur, making timely remediation important.

Generated by OpenCVE AI on September 4, 2026 at 18:09 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11305 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11305 7.5SJ11306 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11306 7.4SJ11307 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11307 7.3SJ11308 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11308 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release 5770‑SS1 or install the specific PTFs—SJ11305 for 7.6, SJ11306 for 7.5, SJ11307 for 7.4, SJ11308 for 7.3.
  • Disable the debug server or restrict its access to trusted administrative accounts only.
  • Ensure that local accounts cannot use the debug server for arbitrary input; enforce least‑privilege and regular patch management to avoid new vulnerabilities.

Generated by OpenCVE AI on September 4, 2026 at 18:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Title IBM i is Affected By Multiple Vulnerabilities in Debug Server
First Time appeared Ibm
Ibm i
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T17:30:43.375Z

Reserved: 2026-07-26T17:10:40.328Z

Link: CVE-2026-17499

cve-icon Vulnrichment

Updated: 2026-09-04T17:30:39.327Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:54.937

Modified: 2026-09-09T15:41:31.140

Link: CVE-2026-17499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T21:00:12Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')