Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a time-of-check to time-of-use (TOCTOU) race condition.
Published: 2026-09-14
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Ownership Hijack
Action: Apply Patch
AI Analysis

Impact

The flaw is a time‑of‑check to time‑of‑use race condition in the SQL query engine of IBM i, affecting versions 7.3 through 7.6. The vulnerability allows a local attacker to change the ownership of arbitrary file‑system objects, which can be leveraged to gain higher privileges, modify or delete data, or disrupt service availability. This corresponds to CWE‑367. The impact is limited to local users but can result in system‑wide compromise if the corrupted ownership grants administrative access.

Affected Systems

IBM i 7.3, 7.4, 7.5, and 7.6 are affected. The affected vendors and product are IBM and IBM i respectively.

Risk and Exploitability

The CVSS score of 6 renders the vulnerability medium severity, while the EPSS score of less than 1% indicates that exploitation events are infrequent. The issue is not listed in CISA’s KEV catalog, suggesting that no widespread, documented exploitation is known. Attackers must first gain local system access to the target IBM i instance and then trigger the SQL query engine in a manner that creates the TOCTOU condition. Once the race is resolved, ownership hijack of file‑system objects may occur, potentially enabling privilege escalation or denial of service. The vulnerability’s exploitability is constrained by the need for local access, but in environments with many local users the risk should still be considered significant.

Generated by OpenCVE AI on September 17, 2026 at 19:22 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ11015 SJ11017 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11015 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11017 7.5SJ11007 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11007 7.4SJ10970 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10970 7.3SJ10969 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10969 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770‑SS1 PTFs: for 7.6 install SJ11015 and SJ11017; for 7.5 install SJ11007; for 7.4 install SJ10970; for 7.3 install SJ10969.
  • If the system is running an unsupported release of IBM i that lacks these PTFs, upgrade to a supported, fixed version of IBM i.
  • When patching cannot be performed immediately, restrict local user privileges that allow file‑ownership changes and isolate or harden the SQL query engine process to limit unauthorized manipulation of file‑system objects.

Generated by OpenCVE AI on September 17, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a time-of-check to time-of-use (TOCTOU) race condition.
Title IBM i is Affected By A Race Condition Vulnerability in SQL Query Engine []
First Time appeared Ibm
Ibm i
Weaknesses CWE-367
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:31:47.152Z

Reserved: 2026-07-28T14:55:49.239Z

Link: CVE-2026-18069

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:48.899Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:04.217

Modified: 2026-09-16T19:24:44.153

Link: CVE-2026-18069

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition