Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Published: 2026-08-12
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in IBM i versions 7.3 through 7.6 permits a remote authenticated attacker to execute arbitrary operating‑system commands. The flaw arises from failure to properly neutralize special elements that are incorporated into OS command strings. Successful exploitation would give the attacker full control over the target system, enabling data theft, tampering, or further lateral movement.

Affected Systems

IBM i Release 7.6, 7.5, 7.4, and 7.3 are affected. The vulnerability applies to installations running the specified releases, as identified by the vendor/product name IBM i and the listed version ranges. Users of IBM i 7.3, 7.4, 7.5, or 7.6 must verify whether the latest patch set forms are in place. All versions currently supported by IBM are included.

Risk and Exploitability

CVSS score of 8.8 classifies this flaw as high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote over authenticated connections; the attacker must possess valid credentials or administrative access to the system. The ability to run arbitrary commands poses a severe threat to confidentiality, integrity, and availability of the affected IBM i environment.

Generated by OpenCVE AI on August 12, 2026 at 22:35 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10968 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10967 7.4SJ10966 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10966 7.3SJ10964 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10964 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTF SJ10968 to IBM i 7.6 to fix the issue.
  • Apply the IBM i PTF SJ10966 to IBM i 7.4 to fix the issue.
  • Apply the IBM i PTF SJ10964 to IBM i 7.3 to fix the issue.

Generated by OpenCVE AI on August 12, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Title IBM i is Affected By Remote Code Execution Vulnerabilities [, ]
First Time appeared Ibm
Ibm i
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T13:19:23.107Z

Reserved: 2026-07-27T21:51:43.277Z

Link: CVE-2026-17642

cve-icon Vulnrichment

Updated: 2026-08-13T13:19:18.619Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T20:17:40.550

Modified: 2026-08-17T17:50:00.757

Link: CVE-2026-17642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T22:45:10Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')